Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

SCADA:ABB-WSERVER-CMD-EXEC

Severity

High

Recommended

Yes

Recommended Action

Drop

Category

SCADA

Keywords

ABB MicroSCADA Wserver Component Arbitrary Command Execution

Release Date

2013/12/16

Update Number

2327

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

SCADA: ABB MicroSCADA Wserver Component Arbitrary Command Execution


This signature detects attempts to exploit a known vulnerability against the Wserver component of ABB MicroSCADA. It is because user controlled data is passed as command line arguments to the CreateProcessA function enabling arbitrary command execution without access control. A remote unauthenticated attacker can exploit this vulnerability by sending requests with the EXECUTE opcode to the vulnerable service. Successful exploitation could lead to arbitrary command execution in the context of the Wserver process.

References

  • BugTraq: 63901

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out