CVE-2019-10967: Buffer Overflow
In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long file name from the LIST command to the FTP service, which may cause the service to overwrite buffers, leading to remote code execution and escalation of privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10967?
CVE-2019-10967 is a stack-based buffer overflow vulnerability in Emerson Ovation OCR400 Controller 3.3.1 and earlier.
What is the severity of CVE-2019-10967?
The severity of CVE-2019-10967 is high with a CVSS score of 8.8.
How does CVE-2019-10967 affect Emerson Ovation OCR400 firmware?
CVE-2019-10967 affects Emerson Ovation OCR400 firmware versions up to and including 3.3.1.
What is the impact of CVE-2019-10967?
CVE-2019-10967 can lead to remote code execution due to a buffer overflow vulnerability in the embedded FTP server.
Is Emerson Ovation OCR400 vulnerable to CVE-2019-10967?
No, Emerson Ovation OCR400 is not vulnerable to CVE-2019-10967.