peter bassill · operator
$ cve CVE-2016-8377 JSON

CVE-2016-8377 EXPLOIT

8.0
HIGH · CVSS 3.1 · EPSS 8.9% (pctl 95)

Patch early

A public exploit exists.

Description

An issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701. A stack-based buffer overflow vulnerability exists when the software application connects to a malicious server, resulting in a stack buffer overflow. This causes an exploitable Structured Exception Handler (SEH) overwrite condition that may allow remote code execution.

Scoring

CVSS8.0 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS8.91% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2017-02-13
Last modified2026-06-17

Affected (2)

VendorProduct
fatekplc winproladder
fatekplc winproladder firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD