Skip to main navigation Skip to main content Skip to page footer

.NET Deserialization Vulnerability in Client–Server Communication

Security Advisories IBA-2026-08

绿色背景带有圆形数字界面设计。
Publishing Date 2026-06-17
Last Update 2026-06-17
Tracking IDIBA-2026-08
CVECVE-2026-8024
CVSS Base Score9.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Summary

A vulnerability has been identified in ibaPDA and ibaDatCoordinator. The affected applications do not properly restrict the .NET BinaryFormatter when deserializing client-server input. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected applications. This is the same issue that exists for the .NET BinaryFormatter: https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300.

Affected products

This applies to all iba products up to the versions listed below:

  • ibaPDA v8.13.4
  • ibaDatCoordinator v4.0.6 

How do I know that I’m affected?

If you have installed any of the products listed above, you are affected.

Mitigation

Restrict connections to localhost

  • (Info: Applies only to ibaPDA. For ibaDatCoordinator, continue with the next step.) Go to I/O Manager → General and deactivate the option "Automatically open necessary ports in Windows Firewall." (If this option remains active, after a restart of ibaPDA or a restart for data acquisition, the firewall will be reconfigured automatically.)
  • Then go to Advanced Windows Firewall settings and delete or deactivate all incoming rules for the ibaPDA / ibaDatCoordinator Client and Server.
  • Create manual firewall rules for the connection you use for ibaPDA or ibaDatCoordinator and verify that you have the correct ports configured. Help regarding which ports the ibaPDA or ibaDatCoordinator Service uses can be found in the iba Help Center.

Important: After the change, verify that all ibaPDA or ibaDatCoordinator services are working as expected and that the data acquisition is functioning correctly.

Solution

With the following versions, the issue has been fixed:

  • ibaPDA v8.14.0
  • ibaDatCoordinator v4.0.7

Customer Actions

Please install the update as described in the solution

Acknowledgements

iba AG thanks the following parties for their efforts:

References

Timeline

2026-04-16Information from Tenable to the Security Team
2026-06-17Fix for the issue in ibaPDA v8.14.0
2026-06-17Fix for the issue in ibaDatCoordinator v4.0.7
返回列表视图

你今天想做什么?

选择国家后,我的请求将转发给 iba AG 负责销售和支持的国家分支机构。隐私政策