Vulnerability CVE-2012-0257


Published: 2012-04-02   Modified: 2012-04-03

Description:
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the Open member, leading to a function-pointer overwrite.

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Invensys -> Archestra application object toolkit 
Invensys -> Foxboro control software 
Invensys -> Infusion control edition 
Invensys -> Infusion foundation edition 
Invensys -> Infusion scada 
Invensys -> Intouch 
Invensys -> Wonderware application server 
Invensys -> Wonderware information server 

 References:
http://www.us-cert.gov/control_systems/pdf/ICSA-12-081-01.pdf
https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000071.pdf
http://secunia.com/advisories/48675
http://osvdb.org/80891

Copyright 2024, cxsecurity.com

 

Back to Top