PatchSiren

Unisys CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Unisys CVE published 2017-02-03

CVE-2015-4049

CVE-2015-4049 describes a remotely reachable, authenticated issue in Unisys MCP-FIRMWARE 40.0 before 40.0IC4 Build 270 on Libra 43xx/63xx/83xx and FS600 class systems. Under the reported conditions, use of program operators during EPSILON (level 5) based codefiles at peak memory usage can trigger CPM stack corruption, resulting in data corruption or a system crash.