CVE-2014-9205
high
CVSS v3
—
CVSS v2
7.5
VIR risk
7.5
Description
Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMOTIC stable before 8.2.19 and PROMOTIC development before 8.3.2 allows remote attackers to execute arbitrary code by providing a large amount of data.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: ics-cert@hq.dhs.gov — http://www.promotic.eu/en/pmdoc/News.htm
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| microsys | promotic | {"endIncluding":"8.2.18"} | |
References
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.