漏洞信息详情
AVEVA InduSoft Web Studio和InTouch Machine Edition 缓冲区错误漏洞
漏洞简介
AVEVA InduSoft Web Studio和InTouch Machine Edition都是英国AVEVA Group plc公司的产品。AVEVA InduSoft Web Studio是一套工控组态软件。InTouch Machine Edition是一套嵌入式HMI软件包。
AVEVA InduSoft Web Studio和InTouch Machine Edition中存在基于栈的缓冲区溢出漏洞。远程攻击者可通过发送特制的数据包利用该漏洞执行代码。以下产品和版本受到影响:AVEVA InduSoft Web Studio 8.1版本和8.1SP1版本;InTouch Machine Edition 2017 8.1版本,2017 8.1 SP1版本。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec128%28002%29.pdf
参考网址
来源:MISC
链接:https://www.tenable.com/security/research/tra-2018-19
来源:CONFIRM
链接:https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec128(002).pdf
来源:BID
链接:https://www.securityfocus.com/bid/104870
来源:MISC
链接:https://ics-cert.us-cert.gov/advisories/ICSA-18-200-01
受影响实体
- Aveva Intouch_machine_2017:8.1:Sp1<!--2000-1-1-->
- Aveva Indusoft_web_studio:8.1:Sp1<!--2000-1-1-->
- Aveva Intouch_machine_2017:8.1<!--2000-1-1-->
- Aveva Indusoft_web_studio:8.1<!--2000-1-1-->
补丁
- AVEVA InduSoft Web Studio和InTouch Machine Edition 缓冲区错误漏洞的修复措施<!--2018-7-19-->
还没有评论,来说两句吧...