{"api_version":"1","generated_at":"2026-07-23T07:35:41+00:00","cve":"CVE-2012-3008","urls":{"html":"https://cve.report/CVE-2012-3008","api":"https://cve.report/api/cve/CVE-2012-3008.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-3008","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-3008"},"summary":{"title":"CVE-2012-3008","description":"Stack-based buffer overflow in OSIsoft PI OPC DA Interface before 2.3.20.9 allows remote authenticated users to execute arbitrary code by sending packet data during the processing of messages associated with OPC items.","state":"PUBLISHED","assigner":"icscert","published_at":"2012-07-20 10:40:37","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"8.5","severity":"","vector":"AV:N/AC:M/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/49986","name":"http://secunia.com/advisories/49986","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/54609","name":"http://www.securityfocus.com/bid/54609","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.us-cert.gov/control_systems/pdf/ICSA-12-201-01.pdf","name":"http://www.us-cert.gov/control_systems/pdf/ICSA-12-201-01.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"404 - File Not Found | CISA","mime":"application/pdf","httpstatus":"404","archivestatus":"200"},{"url":"http://osvdb.org/84091","name":"http://osvdb.org/84091","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/77131","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/77131","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-3008","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-3008","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"3008","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"osisoft","cpe5":"pi_opc_da_interface","cpe6":"2.3.16.16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"3008","vulnerable":"1","versionEndIncluding":"2.3.17.18","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"osisoft","cpe5":"pi_opc_da_interface","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T19:50:05.362Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"osisoft-piopcda-opc-bo(77131)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/77131"},{"name":"84091","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/84091"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.us-cert.gov/control_systems/pdf/ICSA-12-201-01.pdf"},{"name":"49986","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/49986"},{"name":"54609","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/54609"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-07-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in OSIsoft PI OPC DA Interface before 2.3.20.9 allows remote authenticated users to execute arbitrary code by sending packet data during the processing of messages associated with OPC items."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-12-21T17:57:01.000Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"name":"osisoft-piopcda-opc-bo(77131)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/77131"},{"name":"84091","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/84091"},{"tags":["x_refsource_MISC"],"url":"http://www.us-cert.gov/control_systems/pdf/ICSA-12-201-01.pdf"},{"name":"49986","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/49986"},{"name":"54609","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/54609"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2012-3008","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in OSIsoft PI OPC DA Interface before 2.3.20.9 allows remote authenticated users to execute arbitrary code by sending packet data during the processing of messages associated with OPC items."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"osisoft-piopcda-opc-bo(77131)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/77131"},{"name":"84091","refsource":"OSVDB","url":"http://osvdb.org/84091"},{"name":"http://www.us-cert.gov/control_systems/pdf/ICSA-12-201-01.pdf","refsource":"MISC","url":"http://www.us-cert.gov/control_systems/pdf/ICSA-12-201-01.pdf"},{"name":"49986","refsource":"SECUNIA","url":"http://secunia.com/advisories/49986"},{"name":"54609","refsource":"BID","url":"http://www.securityfocus.com/bid/54609"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2012-3008","datePublished":"2012-07-20T10:00:00.000Z","dateReserved":"2012-05-30T00:00:00.000Z","dateUpdated":"2024-08-06T19:50:05.362Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-07-20 10:40:37","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:osisoft:pi_opc_da_interface:*:*:*:*:*:*:*:*","versionEndIncluding":"2.3.17.18","matchCriteriaId":"8DBD4394-46E8-44AE-B1D9-EF9DD5B81F0A"},{"vulnerable":true,"criteria":"cpe:2.3:a:osisoft:pi_opc_da_interface:2.3.16.16:*:*:*:*:*:*:*","matchCriteriaId":"1A5E37CC-21DC-4E93-AAC0-C11F96121178"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"3008","Ordinal":"1","Title":"CVE-2012-3008","CVE":"CVE-2012-3008","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"3008","Ordinal":"1","NoteData":"Stack-based buffer overflow in OSIsoft PI OPC DA Interface before 2.3.20.9 allows remote authenticated users to execute arbitrary code by sending packet data during the processing of messages associated with OPC items.","Type":"Description","Title":"CVE-2012-3008"},{"CveYear":"2012","CveId":"3008","Ordinal":"2","NoteData":"2012-07-20","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"3008","Ordinal":"3","NoteData":"2017-12-21","Type":"Other","Title":"Modified"}]}}}