9.8
CVE-2018-14807
- EPSS 4.63%
- Veröffentlicht 18.10.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:49:50
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
A stack-based buffer overflow vulnerability in Opto 22 PAC Control Basic and PAC Control Professional versions R10.0a and prior may allow remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opto22 ≫ Pac Control Editionbasic Version <= r10.0a
Opto22 ≫ Pac Control Editionprofessional Version <= r10.0a
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.63% | 0.882 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-121 Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.