CVE-2015-6484: Null Pointer Dereference
Published Oct 25, 2015
·Updated
3S-Smart CODESYS Gateway Server before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted (1) GET or (2) POST request.
Affected Software
1 affected component
3S-Smart Software Solutions Codesys Gateway Server<=2.3.9.47
Event History
Oct 25, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6484?
CVE-2015-6484 has been classified as a medium severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2015-6484?
To remediate CVE-2015-6484, upgrade the CODESYS Gateway Server to version 2.3.9.48 or later.
3
What type of attacks can exploit CVE-2015-6484?
CVE-2015-6484 can be exploited through crafted GET or POST requests that trigger a null pointer dereference in the server.
4
Which versions of CODESYS Gateway Server are affected by CVE-2015-6484?
CVE-2015-6484 affects CODESYS Gateway Server versions up to and including 2.3.9.47.
5
What is the impact of exploiting CVE-2015-6484?
Exploiting CVE-2015-6484 can lead to a denial of service, causing the daemon to crash.