CVE-2017-12732: Buffer Overflow
Published Oct 5, 2017
·Updated
A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet length. The next packet length is not verified, allowing a buffer overwrite that could lead to an arbitrary remote code execution.
Affected Software
1 affected component
GE Intelligent Platforms Proficy Hmi\/scada Cimplicity<=9.0
Event History
Oct 5, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-12732?
CVE-2017-12732 is considered critical due to the potential for arbitrary remote code execution.
2
How do I fix CVE-2017-12732?
To mitigate CVE-2017-12732, upgrade to a version of GE CIMPLICITY later than 9.0.
3
What software is affected by CVE-2017-12732?
CVE-2017-12732 affects GE CIMPLICITY versions 9.0 and prior.
4
What type of vulnerability is CVE-2017-12732?
CVE-2017-12732 is a stack-based buffer overflow vulnerability.
5
What could be the impact of CVE-2017-12732?
The impact of CVE-2017-12732 could lead to remote code execution, allowing attackers to execute arbitrary code on affected systems.