CVE-2011-4039
Published Feb 10, 2012
Last updated 13 years ago
Overview
- Description
- Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access violation."
- Source
- cret@cert.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:dreamreport:dream_report:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F2DD8213-B11B-48BF-A2A1-9F485F02D310", "versionEndIncluding": "3.43" }, { "criteria": "cpe:2.3:a:dreamreport:dream_report:3.21:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E8A91FF-176F-4823-90F3-AA998F54558B" }, { "criteria": "cpe:2.3:a:dreamreport:dream_report:3.41:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CB7D92A-80CA-45C3-8A94-0FE560791D05" }, { "criteria": "cpe:2.3:a:dreamreport:dream_report:3.42:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2E435F35-43CA-46DE-8637-17F84D43E4AF" }, { "criteria": "cpe:2.3:a:invensys:wonderware_hmi_reports:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "97C412F4-B6C6-4000-8828-16A2B0AF9262", "versionEndIncluding": "3.42.835.0304" } ], "operator": "OR" } ] } ]