ID

VAR-201203-0406


TITLE

TwinCAT Scope 'TCatScopeView.exe' Heap Buffer Overflow Vulnerability

Trust: 0.8

sources: IVD: 8719fa5a-1f71-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-1066

DESCRIPTION

TwinCAT is an industrial automation product. TwinCAT has a security hole that allows malicious users to control the application. The TCatScopeView.exe tool has an error when processing the Scope view file. The attacker builds a specially crafted SVW file to trick the user into parsing, triggering a heap-based buffer overflow, and successfully exploiting the vulnerability to execute arbitrary code in the application context. TwinCAT Scope is prone to a heap-based buffer-overflow vulnerability because it fails to properly validate user-supplied input. Failed exploit attempts will likely result in a denial-of-service condition. TwinCAT Scope 2.9.0.226 is vulnerable; other versions may also be affected

Trust: 0.99

sources: CNVD: CNVD-2012-1066 // BID: 52294 // IVD: 8719fa5a-1f71-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 8719fa5a-1f71-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-1066

AFFECTED PRODUCTS

vendor:beckhoffmodel:automation twincat scopescope:eqversion:2.9.0.226

Trust: 1.1

vendor:beckhoffmodel:automation twincat r2 buildscope:eqversion:2.112038

Trust: 0.9

vendor:beckhoffmodel:automation twincat r2 buildscope:eqversion:2.112038*

Trust: 0.2

sources: IVD: 8719fa5a-1f71-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-1066 // BID: 52294

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 8719fa5a-1f71-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

IVD: 8719fa5a-1f71-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 8719fa5a-1f71-11e6-abef-000c29c66e3d

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201203-062

TYPE

Buffer overflow

Trust: 0.8

sources: IVD: 8719fa5a-1f71-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201203-062

EXTERNAL IDS

db:BIDid:52294

Trust: 1.5

db:CNVDid:CNVD-2012-1066

Trust: 0.8

db:CNNVDid:CNNVD-201203-062

Trust: 0.6

db:IVDid:8719FA5A-1F71-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 8719fa5a-1f71-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-1066 // BID: 52294 // CNNVD: CNNVD-201203-062

REFERENCES

url:http://aluigi.altervista.org/adv/twincat_2-adv.txthttp

Trust: 0.6

url:http://www.securityfocus.com/bid/52294

Trust: 0.6

url:http://beckhoff.de/english.asp?twincat/overvw.htm

Trust: 0.3

url:http://aluigi.altervista.org/adv/twincat_2-adv.txt

Trust: 0.3

sources: CNVD: CNVD-2012-1066 // BID: 52294 // CNNVD: CNNVD-201203-062

CREDITS

Luigi Auriemma

Trust: 0.9

sources: BID: 52294 // CNNVD: CNNVD-201203-062

SOURCES

db:IVDid:8719fa5a-1f71-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2012-1066
db:BIDid:52294
db:CNNVDid:CNNVD-201203-062

LAST UPDATE DATE

2022-05-17T02:09:57.732000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2012-1066date:2012-03-07T00:00:00
db:BIDid:52294date:2012-03-05T00:00:00
db:CNNVDid:CNNVD-201203-062date:2012-03-07T00:00:00

SOURCES RELEASE DATE

db:IVDid:8719fa5a-1f71-11e6-abef-000c29c66e3ddate:2012-03-07T00:00:00
db:CNVDid:CNVD-2012-1066date:2012-03-07T00:00:00
db:BIDid:52294date:2012-03-05T00:00:00
db:CNNVDid:CNNVD-201203-062date:2012-03-07T00:00:00