In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based...
Vulnerability Description
In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long file name from the LIST command to the FTP service, which may cause the service to overwrite buffers, leading to remote code execution and escalation of privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-10967
Credits & Attribution
No credits recorded in the NVD database.
References
More from Emerson
View All →Affected Vendor
Emerson
View all reports →