Vulnerability Description
Multiple heap-based buffer overflows in 3S-Smart CODESYS Gateway Server before 2.3.9.34 allow remote attackers to execute arbitrary code via opcode (1) 0x3ef or (2) 0x3f0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 3S-Smart | Codesys Gateway Server | < 2.3.9.34 |
Related Weaknesses (CWE)
References
- http://zerodayinitiative.com/advisories/ZDI-15-441/Third Party AdvisoryVDB Entry
- http://zerodayinitiative.com/advisories/ZDI-15-442/Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-15-258-02Third Party AdvisoryUS Government Resource
- http://zerodayinitiative.com/advisories/ZDI-15-441/Third Party AdvisoryVDB Entry
- http://zerodayinitiative.com/advisories/ZDI-15-442/Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-15-258-02Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2015-6460?
CVE-2015-6460 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple heap-based buffer overflows in 3S-Smart CODESYS Gateway Server before 2.3.9.34 allow remote attackers to execute arbitrary code via opcode (1) 0x3ef or (2) 0x3f0.
How severe is CVE-2015-6460?
CVE-2015-6460 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-6460?
Check the references section above for vendor advisories and patch information. Affected products include: 3S-Smart Codesys Gateway Server.