CVE-2015-6460: Buffer Overflow
Published Sep 18, 2015
·Updated
Multiple heap-based buffer overflows in 3S-Smart CODESYS Gateway Server before 2.3.9.34 allow remote attackers to execute arbitrary code via opcode (1) 0x3ef or (2) 0x3f0.
Affected Software
1 affected component
3S-Smart CODESYS Gateway Server<2.3.9.34
Event History
Sep 18, 2015
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6460?
CVE-2015-6460 has a critical severity rating due to the potential for remote code execution.
2
How do I fix CVE-2015-6460?
To fix CVE-2015-6460, update the CODESYS Gateway Server to version 2.3.9.34 or later.
3
What types of attacks are possible with CVE-2015-6460?
CVE-2015-6460 allows remote attackers to execute arbitrary code on affected systems.
4
Which versions of CODESYS Gateway Server are affected by CVE-2015-6460?
CVE-2015-6460 affects all versions of CODESYS Gateway Server prior to 2.3.9.34.
5
What can users do to mitigate the risks associated with CVE-2015-6460?
To mitigate the risks of CVE-2015-6460, users should restrict access to the CODESYS Gateway Server and apply all relevant patches.