Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data.
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes NUL characters or null bytes when they are sent to a downstream component.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-20-210-01 | third party advisory us government resource |