CVE-2019-10967 Vulnerability Details

  /     /     /  

CVE-2019-10967 Metadata Quick Info

CVE Published: 28/05/2019 | CVE Updated: 04/08/2024 | CVE Year: 2019
Source: icscert | Vendor: Emerson | Product: Emerson Ovation OCR400 Controller
Status : PUBLISHED

CVE-2019-10967 Description

In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long file name from the LIST command to the FTP service, which may cause the service to overwrite buffers, leading to remote code execution and escalation of privileges.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-121
CWE Name: Stack-Based Buffer Overflow CWE-121
Source: Emerson

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).