CVE-2012-0245
Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Module, IRC5 OPC Server, PC SDK, PickMaster 3 and 5, RobView 5, RobotStudio, WebWare SDK, and WebWare Server, allow…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Module, IRC5 OPC Server, PC SDK, PickMaster 3 and 5, RobView 5, RobotStudio, WebWare SDK, and WebWare Server, allow remote attackers to execute arbitrary code via a crafted (1) 0xA or (2) 0xE Netscan packet.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 8.18% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- abb/interlink module · abb/irc5 opc server · abb/pc sdk · abb/pickmaster 3 · abb/pickmaster 5 · abb/robot communications runtime · abb/robotstudio · abb/robview 5 · abb/webware sdk · abb/webware server
- Source
- cret@cert.org
References
- http://archives.neohapsis.com/archives/bugtraq/2012-02/0125.html
- http://secunia.com/advisories/48090Vendor Advisory
- http://www.securityfocus.com/bid/52123
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-059-01.pdfPatch, US Government Resource
- http://www.zerodayinitiative.com/advisories/ZDI-12-033/
- http://www05.abb.com/global/scot/scot348.nsf/veritydisplay/f261be074480dc24c12579a00049ecd5/%24file/si10227a1%20vulnerability%20security%20advisory.pdf
- http://archives.neohapsis.com/archives/bugtraq/2012-02/0125.html
- http://secunia.com/advisories/48090Vendor Advisory
- http://www.securityfocus.com/bid/52123
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-059-01.pdfPatch, US Government Resource
- http://www.zerodayinitiative.com/advisories/ZDI-12-033/
- http://www05.abb.com/global/scot/scot348.nsf/veritydisplay/f261be074480dc24c12579a00049ecd5/%24file/si10227a1%20vulnerability%20security%20advisory.pdf
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.