CVE-2017-6025 - CVE House
Back to Database
Status published Critical CVE-2017-6025

A Stack Buffer Overflow issue was discovered in 3S-Smart Software...

Vulnerability Description

A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A malicious user could overflow the stack buffer by providing overly long strings to functions that handle the XML. Because the function does not verify string size before copying to memory, the attacker may then be able to crash the application or run arbitrary code.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-6025

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

3S-Smart Software Solutions GmbH CODESYS Web Server
Vulnerable Versions:
3S-Smart Software Solutions GmbH CODESYS Web Server

Timeline

Official Publish: May 19th, 2017
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)