The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC ITC1500 V3
- SIMATIC ITC1500 V3 PRO
- SIMATIC ITC1900 V3
- SIMATIC ITC1900 V3 PRO
- SIMATIC ITC2200 V3
- SIMATIC ITC2200 V3 PRO
- Summary
- websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.
- Remediation
- Update to V3.2.1.0 or later version
