First published: Mon Feb 13 2017(Updated: )
An issue was discovered in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0. By sending additional valid packets, an attacker could trigger a stack-based buffer overflow and cause a crash. Also, a malicious attacker can trigger a remote buffer overflow on the Fatek Communication Server.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Fatek Automation FV Designer | =1.2.8.0 | |
Fatek Automation PM Designer V3 | =2.1.2.2 | |
Fatek FvDesigner | =1.2.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5798 is classified as a high severity vulnerability due to its potential for remote code execution and denial of service.
To fix CVE-2016-5798, update Fatek Automation PM Designer to version 2.1.2.3 or later and Fatek Automation FV Designer to version 1.2.8.1 or later.
CVE-2016-5798 is a stack-based buffer overflow vulnerability.
CVE-2016-5798 affects Fatek Automation PM Designer version 2.1.2.2 and Fatek Automation FV Designer version 1.2.8.0.
Yes, CVE-2016-5798 can be exploited remotely by sending specially crafted packets to the affected software.