First published: Fri Dec 17 2010(Updated: )
Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series Batch 8.1 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted request to port 9001.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invensys Wonderware InBatch | =8.1 | |
Invensys Wonderware InBatch | =9.0 | |
Invensys Foxboro I/a Series Batch | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4557 has a high severity rating due to its potential to cause denial of service and execute arbitrary code.
To fix CVE-2010-4557, you should update Invensys Wonderware InBatch and Foxboro I/A Series Batch to the latest security patches.
CVE-2010-4557 affects Invensys Wonderware InBatch versions 8.1 and 9.0, as well as Invensys Foxboro I/A Series Batch version 8.1.
Yes, CVE-2010-4557 can be exploited remotely through crafted requests sent to port 9001.
CVE-2010-4557 is a buffer overflow vulnerability that may lead to denial of service and potentially allow arbitrary code execution.