CVE-2010-4709

critical

Description

Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server before 3.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a MODBUS response packet with a crafted length field.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/64944

http://www.vupen.com/english/advisories/2011/0209

http://www.us-cert.gov/control_systems/pdf/ICSA-10-322-02A.pdf

http://www.kb.cert.org/vuls/id/768840

http://secunia.com/advisories/43029

http://automatedsolutions.com/pub/asmbtcpopc/readme.htm

Details

Source: Mitre, NVD

Published: 2011-01-28

Updated: 2017-08-17

Risk Information

CVSS v2

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical