CVE-2012-0257
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the Open member, leading to a function-pointer overwrite.
Desbordamiento de búfer basado en memoria dinámica en el componente ActiveX WWCabFile en Wonderware System Platform en Invensys Wonderware Application Server 2012 y anteriores, Foxboro Control Software v3.1 y anteriores, InFusion CE/FE/SCADA v2.5 y anteriores, Wonderware Information Server v4.5 y anteriores, ArchestrA Application Object Toolkit v3.2 y anteriores, y InTouch v10.0 hasta v10.5 ,permite a atacantes remotos ejecutar código arbitrario a través de una cadena larga sobre el miembro Open, provocando una sobrescritura de un puntero a función.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-12-21 CVE Reserved
- 2012-04-02 CVE Published
- 2023-11-01 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://osvdb.org/80891 | Vdb Entry | |
http://secunia.com/advisories/48675 | Third Party Advisory | |
http://www.us-cert.gov/control_systems/pdf/ICSA-12-081-01.pdf | Us Government Resource | |
https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000071.pdf | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Invensys Search vendor "Invensys" | Archestra Application Object Toolkit Search vendor "Invensys" for product "Archestra Application Object Toolkit" | <= 3.2 Search vendor "Invensys" for product "Archestra Application Object Toolkit" and version " <= 3.2" | - |
Affected
| ||||||
Invensys Search vendor "Invensys" | Foxboro Control Software Search vendor "Invensys" for product "Foxboro Control Software" | <= 3.1 Search vendor "Invensys" for product "Foxboro Control Software" and version " <= 3.1" | - |
Affected
| ||||||
Invensys Search vendor "Invensys" | Infusion Control Edition Search vendor "Invensys" for product "Infusion Control Edition" | <= 2.5 Search vendor "Invensys" for product "Infusion Control Edition" and version " <= 2.5" | - |
Affected
| ||||||
Invensys Search vendor "Invensys" | Infusion Foundation Edition Search vendor "Invensys" for product "Infusion Foundation Edition" | <= 2.5 Search vendor "Invensys" for product "Infusion Foundation Edition" and version " <= 2.5" | - |
Affected
| ||||||
Invensys Search vendor "Invensys" | Infusion Scada Search vendor "Invensys" for product "Infusion Scada" | <= 2.5 Search vendor "Invensys" for product "Infusion Scada" and version " <= 2.5" | - |
Affected
| ||||||
Invensys Search vendor "Invensys" | Intouch Search vendor "Invensys" for product "Intouch" | 10.0 Search vendor "Invensys" for product "Intouch" and version "10.0" | - |
Affected
| ||||||
Invensys Search vendor "Invensys" | Intouch Search vendor "Invensys" for product "Intouch" | 10.5 Search vendor "Invensys" for product "Intouch" and version "10.5" | - |
Affected
| ||||||
Invensys Search vendor "Invensys" | Wonderware Application Server Search vendor "Invensys" for product "Wonderware Application Server" | <= 2012 Search vendor "Invensys" for product "Wonderware Application Server" and version " <= 2012" | - |
Affected
| ||||||
Invensys Search vendor "Invensys" | Wonderware Information Server Search vendor "Invensys" for product "Wonderware Information Server" | <= 4.5 Search vendor "Invensys" for product "Wonderware Information Server" and version " <= 4.5" | - |
Affected
| ||||||
Invensys Search vendor "Invensys" | Wonderware Information Server Search vendor "Invensys" for product "Wonderware Information Server" | 3.1 Search vendor "Invensys" for product "Wonderware Information Server" and version "3.1" | - |
Affected
| ||||||
Invensys Search vendor "Invensys" | Wonderware Information Server Search vendor "Invensys" for product "Wonderware Information Server" | 4.0 Search vendor "Invensys" for product "Wonderware Information Server" and version "4.0" | - |
Affected
| ||||||
Invensys Search vendor "Invensys" | Wonderware Information Server Search vendor "Invensys" for product "Wonderware Information Server" | 4.0 Search vendor "Invensys" for product "Wonderware Information Server" and version "4.0" | sp1 |
Affected
|