ID

VAR-201102-0386


TITLE

Moxa Device Manager 'MDMUtil.dll' Remote Buffer Overflow Vulnerability

Trust: 1.1

sources: IVD: 3194b68a-1fa1-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-0456 // BID: 46156

DESCRIPTION

Moxa Device Manager is a remote management tool for Moxa's embedded computers. The \"MDMUtil.dll\" module has a boundary error when processing certain messages, tempting the user to link to a malicious MDM gateway to trigger a stack-based buffer overflow. Successful exploitation of a vulnerability can execute arbitrary instructions in an application security context. Failed exploit attempts will result in a denial-of-service condition

Trust: 0.99

sources: CNVD: CNVD-2011-0456 // BID: 46156 // IVD: 3194b68a-1fa1-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 3194b68a-1fa1-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-0456

AFFECTED PRODUCTS

vendor:moxamodel:device managerscope:eqversion:2.3

Trust: 0.8

vendor:moxamodel:device managerscope:eqversion:2.1

Trust: 0.3

vendor:moxamodel:device managerscope:neversion:2.3

Trust: 0.3

sources: IVD: 3194b68a-1fa1-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-0456 // BID: 46156

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 3194b68a-1fa1-11e6-abef-000c29c66e3d
value: LOW

Trust: 0.2

IVD: 3194b68a-1fa1-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 3194b68a-1fa1-11e6-abef-000c29c66e3d

THREAT TYPE

network

Trust: 0.3

sources: BID: 46156

TYPE

Boundary Condition Error

Trust: 0.3

sources: BID: 46156

PATCH

title:Moxa Device Manager 'MDMUtil.dll' Remote Buffer Overflow Vulnerability Patchurl:https://www.cnvd.org.cn/patchinfo/show/2823

Trust: 0.6

sources: CNVD: CNVD-2011-0456

EXTERNAL IDS

db:BIDid:46156

Trust: 0.9

db:CNVDid:CNVD-2011-0456

Trust: 0.8

db:ICS CERT ALERTid:ICS-ALERT-10-293-02

Trust: 0.3

db:IVDid:3194B68A-1FA1-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 3194b68a-1fa1-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-0456 // BID: 46156

REFERENCES

url:http://reversemode.com/index.php?option=com_content&task=view&id=70&itemid=1http

Trust: 0.6

url:http://www.moxa.com/product/moxa_device_manager.htm

Trust: 0.3

url:http://reversemode.com/index.php?option=com_content&task=view&id=70&itemid=1

Trust: 0.3

url:http://www.us-cert.gov/control_systems/pdf/ics-alert-10-293-02.pdf

Trust: 0.3

sources: CNVD: CNVD-2011-0456 // BID: 46156

CREDITS

Rubén Santamarta

Trust: 0.3

sources: BID: 46156

SOURCES

db:IVDid:3194b68a-1fa1-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2011-0456
db:BIDid:46156

LAST UPDATE DATE

2022-05-17T01:45:41.508000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-0456date:2011-02-05T00:00:00
db:BIDid:46156date:2011-02-04T00:00:00

SOURCES RELEASE DATE

db:IVDid:3194b68a-1fa1-11e6-abef-000c29c66e3ddate:2011-02-05T00:00:00
db:CNVDid:CNVD-2011-0456date:2011-02-05T00:00:00
db:BIDid:46156date:2011-02-04T00:00:00