CVE-2012-4691 Detail

Current Description

Memory leak in Siemens Automation License Manager (ALM) 4.x and 5.x before 5.2 allows remote attackers to cause a denial of service (memory consumption) via crafted packets.

Evaluator Impact

Per: "The attacker must have access to the local subnet where ALM is located. During installation, the default setting of the Windows firewall is to block the port used by ALM for all networks except the local subnet. If this setting has not been changed by the administrator, these vulnerabilities cannot be exploited from remote networks. Additionally, communication to this port should be blocked at network borders using appropriate security measures like firewalls."

References to Advisories, Solutions, and Tools

Weakness Enumeration

CWE-ID CWE Name Source
CWE-399 Resource Management Errors NIST  

