{"api_version":"1","generated_at":"2026-07-23T09:35:51+00:00","cve":"CVE-2007-4827","urls":{"html":"https://cve.report/CVE-2007-4827","api":"https://cve.report/api/cve/CVE-2007-4827.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4827","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4827"},"summary":{"title":"CVE-2007-4827","description":"Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-09-19 18:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/25713","name":"http://www.securityfocus.com/bid/25713","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Automated Solutions Modbus RTU/ASCII/TCP Slave ActiveX Control Heap Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/981849","name":"http://www.kb.cert.org/vuls/id/981849","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#981849","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36677","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36677","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.nessus.org/plugins/index.php?view=single&id=26066","name":"http://www.nessus.org/plugins/index.php?view=single&id=26066","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Automated Solutions Modbus Slave MiniHMI.exe ActiveX Modbus/TCP Diagnostic Function Arbitrary Code Execution | Tenable™","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/479967/100/0/threaded","name":"http://www.securityfocus.com/archive/1/479967/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.automatedsolutions.com/pub/asmbslv/ReadMe.htm","name":"http://www.automatedsolutions.com/pub/asmbslv/ReadMe.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Automated Solutions Modbus Slave ActiveX Control revision history","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://dvlabs.tippingpoint.com/advisory/TPTI-07-15","name":"http://dvlabs.tippingpoint.com/advisory/TPTI-07-15","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"TippingPoint | DVLabs |","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/38259","name":"http://osvdb.org/38259","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1018707","name":"http://www.securitytracker.com/id?1018707","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Modbus 'MiniHMI.exe' ActiveX Control Heap Overflow Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4827","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4827","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4827","vulnerable":"1","versionEndIncluding":"1.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"automated_solutions","cpe5":"modbus_slave_activex_control","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:08:33.691Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"modbus-tcpslave-bo(36677)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36677"},{"name":"1018707","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018707"},{"name":"20070918 TPTI-07-15: Automated Solutions Modbus TCP Slave ActiveX Control Heap Corruption Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/479967/100/0/threaded"},{"name":"38259","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/38259"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://dvlabs.tippingpoint.com/advisory/TPTI-07-15"},{"name":"25713","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25713"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.nessus.org/plugins/index.php?view=single&id=26066"},{"name":"VU#981849","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/981849"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.automatedsolutions.com/pub/asmbslv/ReadMe.htm"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-09-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"modbus-tcpslave-bo(36677)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36677"},{"name":"1018707","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018707"},{"name":"20070918 TPTI-07-15: Automated Solutions Modbus TCP Slave ActiveX Control Heap Corruption Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/479967/100/0/threaded"},{"name":"38259","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/38259"},{"tags":["x_refsource_MISC"],"url":"http://dvlabs.tippingpoint.com/advisory/TPTI-07-15"},{"name":"25713","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25713"},{"tags":["x_refsource_MISC"],"url":"http://www.nessus.org/plugins/index.php?view=single&id=26066"},{"name":"VU#981849","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/981849"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.automatedsolutions.com/pub/asmbslv/ReadMe.htm"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4827","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"modbus-tcpslave-bo(36677)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36677"},{"name":"1018707","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018707"},{"name":"20070918 TPTI-07-15: Automated Solutions Modbus TCP Slave ActiveX Control Heap Corruption Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/479967/100/0/threaded"},{"name":"38259","refsource":"OSVDB","url":"http://osvdb.org/38259"},{"name":"http://dvlabs.tippingpoint.com/advisory/TPTI-07-15","refsource":"MISC","url":"http://dvlabs.tippingpoint.com/advisory/TPTI-07-15"},{"name":"25713","refsource":"BID","url":"http://www.securityfocus.com/bid/25713"},{"name":"http://www.nessus.org/plugins/index.php?view=single&id=26066","refsource":"MISC","url":"http://www.nessus.org/plugins/index.php?view=single&id=26066"},{"name":"VU#981849","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/981849"},{"name":"http://www.automatedsolutions.com/pub/asmbslv/ReadMe.htm","refsource":"CONFIRM","url":"http://www.automatedsolutions.com/pub/asmbslv/ReadMe.htm"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4827","datePublished":"2007-09-19T18:00:00.000Z","dateReserved":"2007-09-11T00:00:00.000Z","dateUpdated":"2024-08-07T15:08:33.691Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-09-19 18:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:automated_solutions:modbus_slave_activex_control:*:*:*:*:*:*:*:*","versionEndIncluding":"1.4","matchCriteriaId":"4F0D54B4-C438-4EBC-B51C-3F17DF018306"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4827","Ordinal":"1","Title":"CVE-2007-4827","CVE":"CVE-2007-4827","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4827","Ordinal":"1","NoteData":"Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502.","Type":"Description","Title":"CVE-2007-4827"},{"CveYear":"2007","CveId":"4827","Ordinal":"2","NoteData":"2007-09-19","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4827","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}