Lucene search

K
cve[email protected]CVE-2012-4706
HistoryFeb 24, 2013 - 11:48 a.m.

CVE-2012-4706

2013-02-2411:48:21
CWE-189
web.nvd.nist.gov
104
cve-2012-4706
integer signedness error
3s codesys gateway-server
denial of service
heap-based buffer overflow
nvd

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

6.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.8%

Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted packet that triggers a heap-based buffer overflow.

Affected configurations

NVD
Node
3s-softwarecodesys_gateway-serverRange2.3.9.20
OR
3s-softwarecodesys_gateway-serverMatch2.3.5.1
OR
3s-softwarecodesys_gateway-serverMatch2.3.5.2
OR
3s-softwarecodesys_gateway-serverMatch2.3.5.3
OR
3s-softwarecodesys_gateway-serverMatch2.3.6.0
OR
3s-softwarecodesys_gateway-serverMatch2.3.7.0
OR
3s-softwarecodesys_gateway-serverMatch2.3.8.0
OR
3s-softwarecodesys_gateway-serverMatch2.3.8.1
OR
3s-softwarecodesys_gateway-serverMatch2.3.8.2
OR
3s-softwarecodesys_gateway-serverMatch2.3.9
OR
3s-softwarecodesys_gateway-serverMatch2.3.9.1
OR
3s-softwarecodesys_gateway-serverMatch2.3.9.2
OR
3s-softwarecodesys_gateway-serverMatch2.3.9.3
OR
3s-softwarecodesys_gateway-serverMatch2.3.9.4
OR
3s-softwarecodesys_gateway-serverMatch2.3.9.5
OR
3s-softwarecodesys_gateway-serverMatch2.3.9.18
OR
3s-softwarecodesys_gateway-serverMatch2.3.9.19

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

6.8 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.8%