The Baxter Spectrum WBM is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information or cause a Denial of Service (DoS) on the WBM.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
https://www.us-cert.gov/ics/advisories/icsma-22-xxx-xx | broken link |
https://www.cisa.gov/uscert/ics/advisories/icsma-22-251-01 | third party advisory us government resource |