ZDI-20-809: C-MORE HMI EA9 EA-HTTP Improper Input Validation Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of C-More HMI EA9 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the EA-HTTP.exe process. The issue results from the lack of proper input validation prior to further processing user requests. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-20-809?
The severity of ZDI-20-809 is considered critical due to its potential to cause a denial-of-service condition.
How do I fix ZDI-20-809?
To fix ZDI-20-809, it is recommended to update your C-More HMI EA9 software to the latest patched version.
What type of systems are affected by ZDI-20-809?
ZDI-20-809 affects C-More HMI EA9 touch screen panels specifically.
Can ZDI-20-809 be exploited remotely?
Yes, ZDI-20-809 can be exploited remotely as authentication is not required.
What is the impact of ZDI-20-809?
The impact of ZDI-20-809 is a denial-of-service condition which can disrupt the functionality of affected installations.