The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
- Summary
- This vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging to one file into a single long file name. Since the file name characters are copied into a stack variable, a local privileged attacker could use this vulnerability to overflow the kernel stack.
- Remediation
- Update to V1.1 or later version
