CVE-2019-10967
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
28/05/2019
Last modified:
01/10/2020
Description
In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long file name from the LIST command to the FTP service, which may cause the service to overwrite buffers, leading to remote code execution and escalation of privileges.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:emerson:ovation_ocr400_firmware:*:*:*:*:*:*:*:* | 3.3.1 (including) | |
| cpe:2.3:h:emerson:ovation_ocr400:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



