First published: Fri Jul 30 2021(Updated: )
Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson Proficy Machine Edition | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-29297.
The title of the vulnerability is 'Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a ...'
The vulnerability is a buffer overflow in Emerson GE Automation Proficy Machine Edition v8.0, which allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component 'FrameworX.exe' in the module 'MSVCR100.dll'.
The vulnerability affects Emerson GE Automation Proficy Machine Edition v8.0.
The severity of the vulnerability is medium with a CVSS score of 5.3.
The CWEs associated with the vulnerability are CWE-119 and CWE-120.
An attacker can exploit this vulnerability by performing a Man-in-the-Middle (MITM) attack and sending crafted traffic to the 'FrameworX.exe' component in the 'MSVCR100.dll' module.
The vulnerability can cause a denial of service and application crash.
It is recommended to apply the latest patches and updates provided by Emerson to mitigate this vulnerability.
Yes, you can find more information about this vulnerability at the following references: [Link 1](https://github.com/boofish/GE_Proficy_Machine_Edition_vul), [Link 2](https://github.com/boofish/GE_Proficy_Machine_Edition_vul/blob/main/vul1/vul1_steps.pdf).