Skip to main navigation Skip to main content Skip to page footer

.NET Deserialization Vulnerability in Client–Server Communication

Security Advisories IBA-2026-08

Зеленый фон с круговым цифровым интерфейсным дизайном.
Publishing Date 2026-06-17
Last Update 2026-06-17
Tracking IDIBA-2026-08
CVECVE-2026-8024
CVSS Base Score9.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Summary

A vulnerability has been identified in ibaPDA and ibaDatCoordinator. The affected applications do not properly restrict the .NET BinaryFormatter when deserializing client-server input. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected applications. This is the same issue that exists for the .NET BinaryFormatter: https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300.

Affected products

This applies to all iba products up to the versions listed below:

  • ibaPDA v8.13.4
  • ibaDatCoordinator v4.0.6 

How do I know that I’m affected?

If you have installed any of the products listed above, you are affected.

Mitigation

Restrict connections to localhost

  • (Info: Applies only to ibaPDA. For ibaDatCoordinator, continue with the next step.) Go to I/O Manager → General and deactivate the option "Automatically open necessary ports in Windows Firewall." (If this option remains active, after a restart of ibaPDA or a restart for data acquisition, the firewall will be reconfigured automatically.)
  • Then go to Advanced Windows Firewall settings and delete or deactivate all incoming rules for the ibaPDA / ibaDatCoordinator Client and Server.
  • Create manual firewall rules for the connection you use for ibaPDA or ibaDatCoordinator and verify that you have the correct ports configured. Help regarding which ports the ibaPDA or ibaDatCoordinator Service uses can be found in the iba Help Center.

Important: After the change, verify that all ibaPDA or ibaDatCoordinator services are working as expected and that the data acquisition is functioning correctly.

Solution

With the following versions, the issue has been fixed:

  • ibaPDA v8.14.0
  • ibaDatCoordinator v4.0.7

Customer Actions

Please install the update as described in the solution

Acknowledgements

iba AG thanks the following parties for their efforts:

References

Timeline

2026-04-16Information from Tenable to the Security Team
2026-06-17Fix for the issue in ibaPDA v8.14.0
2026-06-17Fix for the issue in ibaDatCoordinator v4.0.7
Вернуться к списку

Что бы Вы хотели сделать сегодня?

Выбрав страну, мой запрос будет направлен в страновое отделение iba AG, отвечающее за продажи и поддержку.Политика конфиденциальности