CVE-2010-2974
Summary
| CVE | CVE-2010-2974 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-08-05 19:17:55 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control in Wonderware Application Server (WAS) before 3.1 SP2 P01, as used in the Wonderware Archestra Integrated Development Environment (IDE) and the InFusion Integrated Engineering Environment (IEE), allows remote attackers to execute arbitrary code via the first argument to the UnsubscribeData method. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Invensys | Infusion Integrated Engineering Environment | All | All | All | All |
| Application | Invensys | Wonderware Application Server | 2.0 | All | All | All |
| Application | Invensys | Wonderware Application Server | 2.1 | All | All | All |
| Application | Invensys | Wonderware Application Server | 3.0 | All | All | All |
| Application | Invensys | Wonderware Application Server | 3.1 | All | All | All |
| Application | Invensys | Wonderware Application Server | 3.1 | sp1 | All | All |
| Application | Invensys | Wonderware Application Server | All | sp2 | All | All |
| Application | Invensys | Wonderware Archestra Configuration Access Component Activex Control | All | All | All | All |
| Application | Invensys | Wonderware Archestra Integrated Development Environment | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VU#703189 - Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control stack buffer overflow | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Invensys Information for VU#703189 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | |
| wdnresource.wonderware.com/support/kbcd/html/1/t002492.htm | af854a3a-2127-422b-91ae-364da2661108 | wdnresource.wonderware.com | |
| www.pacwest.wonderware.com/web/News/NewsDetails.aspx | af854a3a-2127-422b-91ae-364da2661108 | www.pacwest.wonderware.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.