Buffer Overflow Vulnerability in Shanghai Sunfull Automation BACnet Server HMI1002-ARM
CVE-2024-4511
Key Information:
- Vendor
- Shanghai Sunfull Automation
- Status
- Bacnet Server Hmi1002-arm
- Vendor
- CVE Published:
- 6 May 2024
Badges
Summary
A significant buffer overflow vulnerability has been identified in the Shanghai Sunfull Automation BACnet Server HMI1002-ARM 2.0.4, specifically affecting the Message Handler component. This exploitable flaw can potentially allow unauthorized manipulation of memory, resulting in erratic behavior of the server and enabling attackers to execute arbitrary code. Despite early disclosure attempts, there has been no response from the vendor regarding this critical issue. Users of the affected product are strongly urged to exercise caution, monitor system activity, and apply any available security measures until a fix is released. For more information, refer to the details provided by vulnerability databases and advisories.
Affected Version(s)
BACnet Server HMI1002-ARM 2.0.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved