// For flags

CVE-2013-0108

Honeywell HSC Remote Deployer - ActiveX Remote Code Execution

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1, and R410.2; ComfortPoint Open Manager (aka CPO-M) Station R100; and HMIWeb Browser client packages allows remote attackers to execute arbitrary code via a crafted HTML document.

Vulnerabilidad en el control activeX en HscRemoteDeploy.dll en Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, y R410.2; SymmetrE R310, R410.1, y R410.2; ComfortPoint Open Manager (aka CPO-M) Station R100; y los paquetes de los clientes HMIWeb Browser, permiten a atacantes remotos ejecutar código HTML de su elección a través de un documento HTML manipulado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-12-06 CVE Reserved
  • 2013-02-24 CVE Published
  • 2013-03-13 First Exploit
  • 2024-09-16 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Honeywell
Search vendor "Honeywell"
Enterprise Buildings Integrator
Search vendor "Honeywell" for product "Enterprise Buildings Integrator"
r310
Search vendor "Honeywell" for product "Enterprise Buildings Integrator" and version "r310"
-
Affected
Honeywell
Search vendor "Honeywell"
Enterprise Buildings Integrator
Search vendor "Honeywell" for product "Enterprise Buildings Integrator"
r400.2
Search vendor "Honeywell" for product "Enterprise Buildings Integrator" and version "r400.2"
-
Affected
Honeywell
Search vendor "Honeywell"
Enterprise Buildings Integrator
Search vendor "Honeywell" for product "Enterprise Buildings Integrator"
r410.1
Search vendor "Honeywell" for product "Enterprise Buildings Integrator" and version "r410.1"
-
Affected
Honeywell
Search vendor "Honeywell"
Enterprise Buildings Integrator
Search vendor "Honeywell" for product "Enterprise Buildings Integrator"
r410.2
Search vendor "Honeywell" for product "Enterprise Buildings Integrator" and version "r410.2"
-
Affected
Honeywell
Search vendor "Honeywell"
Symmetre
Search vendor "Honeywell" for product "Symmetre"
r310
Search vendor "Honeywell" for product "Symmetre" and version "r310"
-
Affected
Honeywell
Search vendor "Honeywell"
Symmetre
Search vendor "Honeywell" for product "Symmetre"
r400.2
Search vendor "Honeywell" for product "Symmetre" and version "r400.2"
-
Affected
Honeywell
Search vendor "Honeywell"
Symmetre
Search vendor "Honeywell" for product "Symmetre"
r410.1
Search vendor "Honeywell" for product "Symmetre" and version "r410.1"
-
Affected
Honeywell
Search vendor "Honeywell"
Comfortpoint Open Manager Station
Search vendor "Honeywell" for product "Comfortpoint Open Manager Station"
r100
Search vendor "Honeywell" for product "Comfortpoint Open Manager Station" and version "r100"
-
Affected