CVE-2007-4473
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Gesytec Easylon OPC Server before 2.3.44 does not properly validate server handles, which allows remote attackers to execute arbitrary code or cause a denial of service via unspecified network traffic to the OLE for Process Control (OPC) interface, probably related to free operations on arbitrary memory addresses through certain Remove functions, and read and write operations on arbitrary memory addresses through certain Set, Read, and Write functions.
Gesytec Easylon OPC Server anterior a 2.3.44 no valida adecuadamente manejadores de servidor, lo cual permite a atacantes remotos ejecutar código de su elección o provocar denegación de servicio a través de un tráfico de red específico en el OLE para las interfaces Process Control (OPC), probablemente relacionado con operaciones libres sobre direcciones de memoria de su elección a través de ciertas funciones Remove, y leer y escribir operaciones sobre direcciones de memoria de su elección a través de ciertas funciones para asignar, leer y escribir.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-08-22 CVE Reserved
- 2007-12-17 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://osvdb.org/42650 | Vdb Entry | |
http://secunia.com/advisories/28079 | Third Party Advisory | |
http://www.neutralbit.com/downloads/NB-NB-001-EXT-OPC%20Security%20Testing.pdf | X_refsource_misc | |
http://www.neutralbit.com/en/rd/opctest | X_refsource_misc | |
http://www.securityfocus.com/bid/26876 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39062 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.kb.cert.org/vuls/id/205073 | 2017-07-29 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gesytec Easylon Search vendor "Gesytec Easylon" | Opc Server Search vendor "Gesytec Easylon" for product "Opc Server" | 2.30.32 Search vendor "Gesytec Easylon" for product "Opc Server" and version "2.30.32" | - |
Affected
|