Beetel Connection Manager NetConfig.ini Stack-Based Buffer Overflow
Vulnerability Description
A stack-based buffer overflow vulnerability exists in Beetel Connection Manager version PCW_BTLINDV1.0.0B04 when parsing the UserName parameter in the NetConfig.ini configuration file. A crafted .ini file containing an overly long UserName value can overwrite the Structured Exception Handler (SEH), leading to arbitrary code execution when the application processes the file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-10036
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- metacom
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/fileformat/beetel_netconfig_ini_bof.rb
- https://www.exploit-db.com/exploits/28969
- https://www.fortiguard.com/encyclopedia/ips/37394/beetel-connection-manager-netconfig-username-buffer-overflow
- https://www.vulncheck.com/advisories/beetel-connection-manager-stack-based-buffer-overflow
Affected Vendor
Beetel Teletech Ltd.
View all reports →