CVE-2016-4496 Information

Description

Panasonic FPWIN Pro 5.x through 7.x before 7.130 allows local users to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by triggering a crafted index value as demonstrated by an integer overflow.

CVSS Vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

Reference

http://www.securityfocus.com/bid/90520 http://zerodayinitiative.com/advisories/ZDI-16-333/ http://zerodayinitiative.com/advisories/ZDI-16-335/ http://zerodayinitiative.com/advisories/ZDI-16-336/ http://zerodayinitiative.com/advisories/ZDI-16-337/ https://ics-cert.us-cert.gov/advisories/ICSA-16-131-01

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

LOW

Base Severity

4.2

Share on: