Lucene search

K
cve[email protected]CVE-2015-10123
HistoryMar 13, 2024 - 9:15 a.m.

CVE-2015-10123

2024-03-1309:15:06
CWE-120
web.nvd.nist.gov
10
cve-2015-10123
buffer overflow
remote attacker
web-based management
information security

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.4 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

39.3%

An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page of the web-based management a buffer overflow will be triggered to gain full access of the device.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Controller BACnet/IP",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW13",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Controller BACnet MS/TP",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW13",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Ethernet Controller 3rd Generation",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW13",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Ethernet Controller 3rd Generation",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW13",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Fieldbus Coupler Ethernet 3rd Generation",
    "vendor": "WAGO",
    "versions": [
      {
        "lessThanOrEqual": "FW13",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.4 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

39.3%

Related for CVE-2015-10123