CVE-2011-5007: Buffer Overflow
Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5007?
CVE-2011-5007 has been classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2011-5007?
To mitigate CVE-2011-5007, upgrade to a version of CoDeSys later than 3.4 SP4 Patch 2.
What systems are affected by CVE-2011-5007?
CVE-2011-5007 affects the CmpWebServer component in CoDeSys 3.4 SP4 Patch 2 and earlier versions, used on ABB AC500 PLCs and potentially other products.
What type of attack is possible with CVE-2011-5007?
CVE-2011-5007 allows for remote attackers to execute arbitrary code by sending a specially crafted long URI to TCP port 8080.
Is CVE-2011-5007 exploitable from the internet?
Yes, CVE-2011-5007 can be exploited remotely over the internet, making it particularly critical to address.