HTTP: WellinTech KingView KingMess Log File Parsing Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the WellinTech KingView SCADA software. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView 6.53, and kingMess.exe 65.50.2011.18049 in KingView 6.55 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted packet.

Affected Products

Wellintech kingview

Short Name
HTTP:STC:DL:KINGVIEW-LOGFILE-BO
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Buffer CVE-2012-4711 File KingMess KingView Log Overflow Parsing WellinTech
Release Date
03/26/2013
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Wellintech

CVSS Score

10.0

Found a potential security threat?