8.8
CVE-2019-10965
- EPSS 9.78%
- Veröffentlicht 28.05.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:15
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a heap-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long command to the FTP service, which may cause memory corruption that halts the controller or leads to remote code execution and escalation of privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emerson ≫ Ovation Ocr400 Firmware Version <= 3.3.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 9.78% | 0.926 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.