CVE-2015-1007
Last modified
CVE-2015-1007 is a vulnerability of currently unknown severity. A specially crafted configuration file could be used to cause a stack-based buffer overflow condition in the OPCTest.exe, which may allow remote code execution on Opto 22 PAC Project Professional versions prior to R9.4008, PAC Project Basic versions prior to R9.4008, PAC Display Basic versions prior to R9.4g, PAC Display Professional versions prior to R9.4g, OptoOPCServer version R9.4c and prior that were installed by PAC Project installer, versions prior to R9.4008, and OptoDataLink version R9.4d and prior that were installed by PAC Project installer, versions prior to R9.4008. Opto 22 suggests upgrading to the new product version as soon as possible.. EPSS estimates a 2.67% chance of exploitation in the next 30 days.
Description
A specially crafted configuration file could be used to cause a stack-based buffer overflow condition in the OPCTest.exe, which may allow remote code execution on Opto 22 PAC Project Professional versions prior to R9.4008, PAC Project Basic versions prior to R9.4008, PAC Display Basic versions prior to R9.4g, PAC Display Professional versions prior to R9.4g, OptoOPCServer version R9.4c and prior that were installed by PAC Project installer, versions prior to R9.4008, and OptoDataLink version R9.4d and prior that were installed by PAC Project installer, versions prior to R9.4008. Opto 22 suggests upgrading to the new product version as soon as possible.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opto22 | Optodatalink | <= r9.4d |
| Opto22 | Optoopcserver | <= r9.4c |
| Opto22 | Pac Display | < r9.4g |
| Opto22 | Pac Project | < r9.4008 |
References
- https://ics-cert.us-cert.gov/advisories/ICSA-15-120-01Third Party Advisory, US Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-15-120-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-1007?
How severe is CVE-2015-1007?
How do I fix CVE-2015-1007?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-10064A vulnerability was found in VictorFerraresi pokemon-databas…9.8
- CVE-2015-10065A vulnerability classified as critical was found in AenBleid…9.8
- CVE-2015-10066A vulnerability was found in tynx wuersch and classified as …9.8
- CVE-2015-10067A vulnerability was found in oznetmaster SSharpSmartThreadPo…8.1
- CVE-2015-10068A vulnerability classified as critical was found in danynab …9.8
- CVE-2015-10069A vulnerability was found in viakondratiuk cash-machine. It …9.8
- CVE-2015-10070A vulnerability was found in copperwall Twiddit. It has been…9.8
- CVE-2015-10071A vulnerability was found in gitter-badger ezpublish-modern-…7.5
- CVE-2015-10072A vulnerability classified as problematic was found in NREL …6.1
- CVE-2015-10073A vulnerability, which was classified as problematic, was fo…9.6
- CVE-2015-10074A vulnerability was found in OpenSeaMap online_chart 1.2. It…6.1
- CVE-2015-10075A vulnerability was found in Custom-Content-Width 1.0. It ha…6.1
Are you affected by CVE-2015-1007?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
