First published: Thu Nov 01 2012(Updated: )
AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SiPass integrated | <=mp2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5409 is rated as a high severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2012-5409, update Siemens SiPass integrated MP2.6 or earlier to the latest patched version provided by the vendor.
CVE-2012-5409 affects Siemens SiPass integrated versions up to and including MP2.6.
CVE-2012-5409 allows attackers to send crafted IOCP RPC messages that can lead to arbitrary code execution on the affected system.
Yes, CVE-2012-5409 can be exploited remotely over an Ethernet network.