CVE-2011-4531

Siemens Automation License Manager < 5.1 - Improper Input Validation

Title source: rule

Description

Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted content in a (1) get_target_ocx_param or (2) send_target_ocx_param command.

Exploits (1)

exploitdb WRITEUP
doswindows
https://www.exploit-db.com/exploits/18165

Scores

EPSS 0.1375
EPSS Percentile 94.1%

Classification

CWE
CWE-20
Status draft

Affected Products (1)

siemens/automation_license_manager < 5.1

Timeline

Published Jan 08, 2012
Tracked Since Feb 18, 2026