Record summary

CVE-2012-5409 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.

Description

AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBSIEMENS Sipass Integrated 2.6 Ethernet Bus - Arbitrary Pointer DereferenceExploitDB exploitby Lucas ApaNot analyzed1 file
ExploitDB

PoC details

References

6