Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Siemens SiPass Integrated 缓冲区错误漏洞
Vulnerability Description
Siemens SiPass integrated是德国西门子(Siemens)公司的一套访问控制和安全系统。 Siemens SiPass integrated MP2.6和较早版本中的服务器中的AscoServer.exe中存在漏洞,该漏洞源于没有正确的处理通过以太网网络接收的IOCP RPC消息。远程攻击者利用该漏洞通过特制的消息,写入数据到任意内存位置从而执行任意代码。目前已知的有任意指针引用攻击和缓冲区溢出攻击。
CVSS Information
N/A
Vulnerability Type
N/A