CVE-2012-5409
published 2012-11-01CVE-2012-5409: AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which…
PriorityP266critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
15.79%
96.5th percentile
AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | sipass_integrated | <= mp2.6 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unauthenticated crafted TCP packets sent to port 4343 targeting AscoServer.exe IOCP RPC message handling; no authentication is required to reach this port. ↗
- →Monitor for exploitation technique targeting Thread Environment Block (TEB) exception handler pointer overwrite following an access violation in AscoServer.exe threads. ↗
- →Alert on large memcpy operations (e.g., n=0xBB8 / 3000 bytes) originating from IOCP message handling within AscoServer.exe, particularly where the destination pointer is user-controlled. ↗
- →Block or alert on all inbound connections to TCP port 4343 from untrusted/external network segments to prevent exploitation of the SiPass server. ↗
- ·The vulnerability exists in the Ethernet Bus communication path; exploitation is possible over LAN/WAN/PSTN wherever AscoServer.exe is reachable on port 4343/TCP without authentication. ↗
- ·Even though ASLR is present, thread data block addresses are stable due to multiple identical threads being spawned, reducing the effectiveness of address randomization as a mitigation. ↗
- ·Exploitation runs under the SYSTEM account context, meaning successful exploitation grants full system privileges. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q4x4-498h-293w: AscoServer
ghsa_unreviewed·2022-05-17
CVE-2012-5409 [HIGH] CWE-119 GHSA-q4x4-498h-293w: AscoServer
AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.
CISA ICS
Siemens SiPass Server Buffer Overflow
cisa_ics·2018-08-27
Siemens SiPass Server Buffer Overflow
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SiPass Server Buffer Overflow
Last RevisedAugust 27, 2018
Alert CodeICSA-12-305-01
OVERVIEW
This advisory provides mitigation details provided by Siemens for a vulnerability that impacts the Siemens SiPass server.
Siemens has reported a buffer overflow vulnerability in the Siemens SiPass server. Lucas Apa of IOActive discovered this vulnerability and reported it directly to Siemens. Siemens has provided mitigations and a software hotfix corrects this vulnerability. Exploitation of this vulnerability would allow an attacker to perform a denial of service (DoS) and possib
No detection rules found.
No writeups or analysis indexed.
http://ics-cert.us-cert.gov/advisories/ICSA-12-305-01http://ioactive.com/pdfs/SIEMENS_Sipass_Integrated_Ethernet_Bus_Arbitrary_Pointer_Dereference_V4.pdfhttp://secunia.com/advisories/50900http://www.osvdb.org/86129http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-938777.pdfhttp://ics-cert.us-cert.gov/advisories/ICSA-12-305-01http://ioactive.com/pdfs/SIEMENS_Sipass_Integrated_Ethernet_Bus_Arbitrary_Pointer_Dereference_V4.pdfhttp://secunia.com/advisories/50900http://www.osvdb.org/86129http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-938777.pdf
2012-11-01
Published