CVE-2011-4530

Siemens Automation License Manager < 5.1 - Improper Input Validation

Title source: rule

Description

Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote attackers to cause a denial of service (exception and daemon crash) via long fields, as demonstrated by fields to the (1) open_session->workstation->NAME or (2) grant->VERSION function.

Exploits (1)

exploitdb WRITEUP
doswindows
https://www.exploit-db.com/exploits/18165

Scores

EPSS 0.1165
EPSS Percentile 93.5%

Classification

CWE
CWE-20
Status draft

Affected Products (1)

siemens/automation_license_manager < 5.1

Timeline

Published Jan 08, 2012
Tracked Since Feb 18, 2026