Short Name |
SCADA:ABB-WSERVER-CMD-EXEC |
---|---|
Severity |
High |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
SCADA |
Keywords |
ABB MicroSCADA Wserver Component Arbitrary Command Execution |
Release Date |
2013/12/16 |
Update Number |
2327 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against the Wserver component of ABB MicroSCADA. It is because user controlled data is passed as command line arguments to the CreateProcessA function enabling arbitrary command execution without access control. A remote unauthenticated attacker can exploit this vulnerability by sending requests with the EXECUTE opcode to the vulnerable service. Successful exploitation could lead to arbitrary command execution in the context of the Wserver process.