CVE-2011-4051
InduSoft WebStudio Unauthenticated Remote Operations Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and process control.
El componente de CEServer en el módulo de agente remoto en InduSoft Web Studio v6.1 y v7.0 no requiere autenticación, lo que permite a atacantes remotos ejecutar código de su elección a través de vectores relacionados con la creación de un archivo, la carga de un archivo DLL, y el control de procesos.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Indusoft Web Studio. Authentication is not required to exploit this vulnerability.
The flaw exists within the Remote Agent component (CEServer.exe) which listens by default on TCP port 4322. When handling incoming requests the process fails to perform any type of authentication. Many available operations allow direct manipulation and creation of files on disk, loading of arbitrary DLLs and process control. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the User.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-10-13 CVE Reserved
- 2011-11-16 CVE Published
- 2012-10-10 First Exploit
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.us-cert.gov/control_systems/pdf/ICSA-11-319-01.pdf | Us Government Resource |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/21837 | 2012-10-10 |
URL | Date | SRC |
---|---|---|
http://www.indusoft.com/hotfixes/hotfixes.php | 2011-12-08 | |
http://www.zerodayinitiative.com/advisories/ZDI-11-330 | 2011-12-08 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Indusoft Search vendor "Indusoft" | Web Studio Search vendor "Indusoft" for product "Web Studio" | 6.1 Search vendor "Indusoft" for product "Web Studio" and version "6.1" | - |
Affected
| ||||||
Indusoft Search vendor "Indusoft" | Web Studio Search vendor "Indusoft" for product "Web Studio" | 7.0 Search vendor "Indusoft" for product "Web Studio" and version "7.0" | - |
Affected
|