PatchSiren

Fatek CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Fatek CVE published 2017-02-13

CVE-2016-8377

CVE-2016-8377 was publicly disclosed on 2017-02-13 and affects Fatek Automation PLC WinProladder Version 3.11 Build 14701. According to the official NVD record, the issue is a stack-based buffer overflow that can be triggered when the application connects to a malicious server, creating an exploitable SEH overwrite condition that may allow remote code execution. NVD rates the issue HIGH with a CVSS 3.1 ve [truncated]

HIGH Fatek CVE published 2017-02-13

CVE-2016-5798

CVE-2016-5798 describes buffer overflow conditions in Fatek Automation PM Designer V3 2.1.2.2, Automation FV Designer 1.2.8.0, and the Fatek Communication Server. According to the NVD record, an attacker can send additional valid packets to trigger a stack-based buffer overflow and crash, and can also trigger a remote buffer overflow on the communication server. NVD assigns a CVSS 3.0 score of 7.5 (HIGH) [truncated]

HIGH Fatek CVE published 2017-02-13

CVE-2016-5796

CVE-2016-5796 is a memory-corruption flaw in Fatek Automation PM Designer V3 2.1.2.2 and Automation FV Designer 1.2.8.0. According to the public record, sending additional valid packets can trigger a crash or potentially arbitrary code execution. NVD scores the issue HIGH (8.8) and maps it to CWE-119.