BACnet OPC Client Buffer Overflow Vulnerability

Strike ID:
E10-6no01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
4
Year:
2010

Description

This strike exploits a stack-based buffer overflow vulnerability in BACnet OPC Client. The vulnerability is due to insufficient validation of user-supplied input when parsing csv files. Opening a specially crafted csv file can lead to arbitrary code execution.

CVE

Bid