"value":"A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel FC72x (All versions < IP8), Cerberus PRO EN X200 Cloud Distribution (All versions < V4.0.5016), Cerberus PRO EN X300 Cloud Distribution (All versions < V4.2.5015), Sinteso FS20 EN Engineering Tool (All versions < MP8), Sinteso FS20 EN Fire Panel FC20 (All versions < MP8), Sinteso FS20 EN X200 Cloud Distribution (All versions < V4.0.5016), Sinteso FS20 EN X300 Cloud Distribution (All versions < V4.2.5015), Sinteso Mobile (All versions < V3.0.0). The network communication library in affected systems does not validate the length of certain X.509 certificate attributes which might result in a stack-based buffer overflow.\r\nThis could allow an unauthenticated remote attacker to execute code on the underlying operating system with root privileges."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",
"cweId":"CWE-120"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Siemens",
"product":{
"product_data":[
{
"product_name":"Cerberus PRO EN Engineering Tool",
"version":{
"version_data":[
{
"version_affected":"<",
"version_name":"0",
"version_value":"IP8"
}
]
}
},
{
"product_name":"Cerberus PRO EN Fire Panel FC72x",
"version":{
"version_data":[
{
"version_affected":"<",
"version_name":"0",
"version_value":"IP8"
}
]
}
},
{
"product_name":"Cerberus PRO EN X200 Cloud Distribution",
"version":{
"version_data":[
{
"version_affected":"<",
"version_name":"0",
"version_value":"V4.0.5016"
}
]
}
},
{
"product_name":"Cerberus PRO EN X300 Cloud Distribution",
"version":{
"version_data":[
{
"version_affected":"<",
"version_name":"0",
"version_value":"V4.2.5015"
}
]
}
},
{
"product_name":"Sinteso FS20 EN Engineering Tool",
"version":{
"version_data":[
{
"version_affected":"<",
"version_name":"0",
"version_value":"MP8"
}
]
}
},
{
"product_name":"Sinteso FS20 EN Fire Panel FC20",
"version":{
"version_data":[
{
"version_affected":"<",
"version_name":"0",
"version_value":"MP8"
}
]
}
},
{
"product_name":"Sinteso FS20 EN X200 Cloud Distribution",
"version":{
"version_data":[
{
"version_affected":"<",
"version_name":"0",
"version_value":"V4.0.5016"
}
]
}
},
{
"product_name":"Sinteso FS20 EN X300 Cloud Distribution",