CVE-2018-10616
ABB Panel Builder ModBus Beckhoff ClockDevice Stack-based Buffer Overflow Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
ABB Panel Builder 800 all versions has an improper input validation vulnerability which may allow an attacker to insert and run arbitrary code on a computer where the affected product is used.
ABB Panel Builder 800 en todas sus versiones tiene una vulnerabilidad de validación de entradas incorrecta que podría permitir que un atacante inserte y ejecute código arbitrario en un ordenador en el que se emplea el producto afectado.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of ABB Panel Builder 800. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of the ClockDevice parameter of the ABB Modbus Beckhoff OPC Driver. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code under the context of an administrator.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-01 CVE Reserved
- 2018-07-18 CVE Published
- 2023-07-12 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/104882 | Broken Link | |
https://ics-cert.us-cert.gov/advisories/ICSA-18-198-01 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://search-ext.abb.com/library/Download.aspx?DocumentID=3BSE092089&Action=Launch | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Abb Search vendor "Abb" | Panel Builder 800 Search vendor "Abb" for product "Panel Builder 800" | - | - |
Affected
|