ZDI-CAN-10527: C-MORE HMI EA9 EA-HTTP Improper Input Validation Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of C-More HMI EA9 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the EA-HTTP.exe process. The issue results from the lack of proper input validation prior to further processing user requests. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-10527?
ZDI-CAN-10527 has been classified as a denial-of-service vulnerability.
How do I fix ZDI-CAN-10527?
To fix ZDI-CAN-10527, it is recommended to apply any security updates provided by C-MORE for the HMI EA9 touch screen panels.
Can ZDI-CAN-10527 be exploited remotely?
Yes, ZDI-CAN-10527 can be exploited remotely without authentication.
What type of devices does ZDI-CAN-10527 affect?
ZDI-CAN-10527 affects C-MORE HMI EA9 touch screen panels.
What process is related to ZDI-CAN-10527?
The vulnerability exists within the EA-HTTP.exe process of the affected devices.