CVE-2011-4529
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
08/01/2012
Last modified:
11/04/2025
Description
Multiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow remote attackers to execute arbitrary code via a long serialid field in an _licensekey command, as demonstrated by the (1) check_licensekey or (2) read_licensekey command.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:siemens:automation_license_manager:*:sp1:*:*:*:*:*:* | 5.1 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://aluigi.altervista.org/adv/almsrvx_1-adv.txt
- http://support.automation.siemens.com/WW/llisapi.dll/57252401?func=ll&objId=57252401&objAction=csView&nodeid0=17323948&lang=en&siteid=cseus&aktprim=0&extranet=standard&viewreg=WW&load=content
- http://support.automation.siemens.com/WW/view/en/114358
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-361-01.pdf
- http://aluigi.altervista.org/adv/almsrvx_1-adv.txt
- http://support.automation.siemens.com/WW/llisapi.dll/57252401?func=ll&objId=57252401&objAction=csView&nodeid0=17323948&lang=en&siteid=cseus&aktprim=0&extranet=standard&viewreg=WW&load=content
- http://support.automation.siemens.com/WW/view/en/114358
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-361-01.pdf