CVE-2016-5796
Sending additional valid packets could allow the attacker to cause a crash or to execute arbitrary code, because of Improper Restriction of Operations within the Bounds of a Memory Buffer.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0. Sending additional valid packets could allow the attacker to cause a crash or to execute arbitrary code, because of Improper Restriction of Operations within the Bounds of a Memory Buffer.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- fatek/automation fv designer · fatek/automation pm designer
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/93105Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-287-06Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/93105Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-287-06Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.