8.8
CVE-2016-2290
- EPSS 1.43%
- Veröffentlicht 06.04.2016 23:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Heap-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allows remote attackers to execute arbitrary code via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Proface Gp-pro Ex Ex-ed Version <= 4.0.4
Schneider-electric ≫ Proface Gp-pro Ex Pfxexedls Version <= 4.0.4
Schneider-electric ≫ Proface Gp-pro Ex Pfxexedv Version <= 4.0.4
Schneider-electric ≫ Proface Gp-pro Ex Pfxexgrpls Version <= 4.0.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.43% | 0.788 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.