Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-5440

EPSS 1.31% · P80
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-5440

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server. Specifically: all Microsoft Windows (also WinCE) based CODESYS web servers running stand-alone Version 2.3, or as part of the CODESYS runtime system running prior to Version V1.1.9.19. A crafted request may cause a buffer overflow and could therefore execute arbitrary code on the web server or lead to a denial-of-service condition due to a crash in the web server.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
栈缓冲区溢出
Source: NVD (National Vulnerability Database)
Vulnerability Title
3S-Smart CODESYS和CODESYS runtime system 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
3S-Smart Software Solutions CODESYS V3 web server是德国3S-Smart Software Solutions公司的一款使用在CODESYS产品中的Web服务器。 3S-Smart CODESYS Web Server 2.3版本和CODESYS runtime system 1.1.9.19之前版本中存在缓冲区错误漏洞。攻击者可通过发送特制的请求利用该漏洞在Web服务器上执行任意代码或造成拒绝服务(崩溃)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-3S-Smart Software Solutions GmbH CODESYS Web Server 3S-Smart Software Solutions GmbH CODESYS Web Server -

II. Public POCs for CVE-2018-5440

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-5440

登录查看更多情报信息。

Same Patch Batch · n/a · 2018-02-15 · 31 CVEs total

CVE-2017-18088Atlassian Bitbucket Server 输入验证漏洞
CVE-2018-0864Microsoft Project Server和SharePoint Enterprise Server 权限许可和访问控制漏洞
CVE-2018-0820Microsoft Windows kernel 权限许可和访问控制问题漏洞
CVE-2018-7057Steelcase RoomWizard 跨站脚本漏洞
CVE-2018-7056Steelcase RoomWizard 信息泄露漏洞
CVE-2018-7055Steelcase RoomWizard 安全漏洞
CVE-2017-18189Sound eXchange 安全漏洞
CVE-2017-12726Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump 安全漏洞
CVE-2017-12725Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump 安全漏洞
CVE-2017-12724Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump 安全漏洞
CVE-2017-12723Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump 安全漏洞
CVE-2017-12722Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump 安全漏洞
CVE-2017-12721Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump 安全漏洞
CVE-2017-12720Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump 访问控制错误漏洞
CVE-2017-12718Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump 缓冲区错误漏洞
CVE-2018-5767Tenda AC15 输入验证漏洞
CVE-2018-7169shadow 安全特征问题漏洞
CVE-2018-7054Irssi 安全漏洞
CVE-2018-7053Irssi 安全漏洞
CVE-2018-7052Irssi 安全漏洞

Showing top 20 of 31 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2018-5440

No comments yet


Leave a comment