Lucene search

K
cveIcscertCVE-2015-7939
HistoryJan 09, 2016 - 2:59 a.m.

CVE-2015-7939

2016-01-0902:59:12
CWE-119
icscert
web.nvd.nist.gov
27
cve
2015
7939
buffer overflow
unitronics
visilogic
oplc
ide
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.601

Percentile

97.9%

Heap-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.09 allows remote attackers to execute arbitrary code via a long vlp filename.

Affected configurations

Nvd
Node
unitronicsvisilogic_oplc_ideRange9.8.0.00
VendorProductVersionCPE
unitronicsvisilogic_oplc_ide*cpe:2.3:a:unitronics:visilogic_oplc_ide:*:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.601

Percentile

97.9%