PatchSiren

Ibhsoftec CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Ibhsoftec CVE published 2017-02-13

CVE-2016-8364

CVE-2016-8364 describes a critical heap-based buffer overflow in IBHsoftec S7-SoftPLC. According to the CVE record, object memory can process a network packet that is larger than the space available, which can lead to memory corruption in versions prior to 4.12b. NVD rates the issue CVSS 3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating a remotely reachable issue with potentially severe impact.