CVE-2011-3330
Published Nov 4, 2011
Last updated 7 years ago
Overview
- Description
- Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers, to execute arbitrary code via an unspecified system parameter.
- Source
- cret@cert.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-119
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:schneider-electric:monitor_pro:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55192234-7471-4348-A0DB-8A95CE8ABAF0", "versionEndIncluding": "7.6" }, { "criteria": "cpe:2.3:a:schneider-electric:opc_factory_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "51947EEF-B5C4-410E-8CBA-6DF4431EDBC9", "versionEndIncluding": "3.34" }, { "criteria": "cpe:2.3:a:schneider-electric:pl7_pro:*:sp5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5561DF43-8E2E-4BA2-89A1-7A1EA5A2BD56", "versionEndIncluding": "4.5" }, { "criteria": "cpe:2.3:a:schneider-electric:telemecanique_driver_pack:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C01C7A57-C188-4593-81CE-5806C72A94CB", "versionEndIncluding": "2.6" }, { "criteria": "cpe:2.3:a:schneider-electric:unity_pro:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8827FFC8-00E7-4FB1-AE76-A1AD12A70AA9", "versionEndIncluding": "6.0" }, { "criteria": "cpe:2.3:a:schneider-electric:vijeo_citect:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "261173CE-D744-4427-ABCB-AD9BA9CCCF25", "versionEndIncluding": "7.20" } ], "operator": "OR" } ] } ]