CVE-2012-5409

critical
Published 2012-11-01 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-938777.pdf

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/50900

Application impact

VendorProductVersionsFixed
siemenssipass_integrated{"endIncluding":"mp2.6"}

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.