A remote overflow exists in CIMPLICITY. CIMPLICITY fails to perform proper bounds checking, resulting in a buffer overflow. With a specially crafted request, an attacker can cause remote code execution, resulting in a loss of confidentiality, and/or integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Integrity,
Loss of Availability
Solution:
Patch / RCS,
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
SCADA
Solution
Upgrade to version 7.0 SIM9 or higher, and/or patch level 6.1 SP6 Hotfix as it has been reported to fix this vulnerability.