9.3
CVSSv2

CVE-2013-0662

Published: 01/04/2014 Updated: 03/02/2022
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 up to and including 3.2 allow remote malicious users to execute arbitrary code via a large buffer-size value in a Modbus Application Header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric concept

schneider-electric modbus serial driver 1.10

schneider-electric modbus serial driver 2.2

schneider-electric modbus serial driver 3.2

schneider-electric modbuscommdtm sl

schneider-electric opc factory server

schneider-electric opc factory server 3.34

schneider-electric opc factory server 3.35

schneider-electric pl7

schneider-electric powersuite

schneider-electric sft2841 13.1

schneider-electric sft2841

schneider-electric somachine 2.0

schneider-electric somachine 3.0

schneider-electric somachine

schneider-electric somove

schneider-electric twidosuite

schneider-electric unity pro 6.0

schneider-electric unity pro

schneider-electric unityloader

schneider electric somachine 3.0

Exploits

# Title: SEIG Modbus 34 - Denial of Service (PoC) # Author: Alejandro Parodi # Date: 2018-08-17 # Vendor Homepage: wwwschneider-electriccom # Software Link: githubcom/hdbreaker/Ricnar-Exploit-Solutions/tree/master/Medium/CVE-2013-0662-SEIG-Modbus-Driver-v334/VERSION%2034 # Version: v34 # Tested on: Windows7 x86 # CVE: CVE-201 ...
# Title: SEIG Modbus 34 - Remote Code Execution # Author: Alejandro Parodi # Date: 2018-08-17 # Vendor Homepage: wwwschneider-electriccom # Software Link: githubcom/hdbreaker/Ricnar-Exploit-Solutions/tree/master/Medium/CVE-2013-0662-SEIG-Modbus-Driver-v334/VERSION%2034 # Version: v34 # Tested on: Windows XP SP3 # CVE: CVE-201 ...
SEIG Modbus version 34 suffers from a remote code execution vulnerability ...
SEIG Modbus version 34 suffers from a denial of service vulnerability ...