CVE-2019-25349

7.5

ScadaApp · scadaApp for iOS

ScadaApp for iOS version 1.1.4.0 is susceptible to a buffer overflow vulnerability in the Servername field, which allows an attacker to cause a denial of service by triggering an application crash.

Executive summary

A buffer overflow vulnerability in ScadaApp for iOS 1.1.4.0 allows local attackers to force an application crash via a maliciously crafted input.

Vulnerability

The application fails to perform adequate boundary checks on user input within the Servername field. An attacker can trigger a denial of service by pasting an oversized buffer (specifically 257 characters) into this field during the authentication process, which does not require prior elevated privileges.

Business impact

The exploitation of this vulnerability results in an application-level denial of service. While the CVSS score of 7.5 suggests high severity, the impact is limited to the availability of the specific application on the affected device. Frequent crashes can disrupt operations for users relying on ScadaApp for critical monitoring or control tasks, potentially leading to productivity loss.

Remediation

Immediate Action: As no official patch is currently identified for this legacy issue, users should discontinue the use of version 1.1.4.0 and check the Apple App Store for any available updates or alternative secure versions provided by the vendor.

Proactive Monitoring: Security teams should review device logs for frequent application termination events associated with the ScadaApp process.

Compensating Controls: Ensure that mobile device management policies restrict the installation of unauthorized or outdated applications on corporate-managed iOS devices.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the Exploit-DB entry 47678.

Analyst recommendation

Given the availability of a functional proof-of-concept, the risk of this vulnerability being used to disrupt service is elevated. Organizations should identify all instances of this application within their environment and prioritize migration to a supported, patched version or remove the software to eliminate the exposure entirely.

Sources

Originally found and disclosed by Luis Martinez, per the CVE Program record.