Invensys Wonderware Info Server ActiveX Control Unspecified Remote Code Execution Vulnerabilities
BID:48976
Info
Invensys Wonderware Info Server ActiveX Control Unspecified Remote Code Execution Vulnerabilities
| Bugtraq ID: | 48976 |
| Class: | Unknown |
| CVE: |
CVE-2011-2962 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2011 12:00AM |
| Updated: | Aug 03 2011 12:00AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Invensys Wonderware Information Server 4.0 SP1 Invensys Wonderware Information Server 4.0 Invensys Wonderware Information Server 3.1 |
| Not Vulnerable: | |
Discussion
Invensys Wonderware Info Server ActiveX Control Unspecified Remote Code Execution Vulnerabilities
Invensys Wonderware Info Server is prone to a multiple unspecified remote code-esecution vulnerabilities in an unspecified ActiveX control.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
Invensys Wonderware Info Server versions 3.1, 4.0, and 4.0 SP1 are vulnerable.
Invensys Wonderware Info Server is prone to a multiple unspecified remote code-esecution vulnerabilities in an unspecified ActiveX control.
Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition.
Invensys Wonderware Info Server versions 3.1, 4.0, and 4.0 SP1 are vulnerable.
Exploit / POC
Invensys Wonderware Info Server ActiveX Control Unspecified Remote Code Execution Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Invensys Wonderware Info Server ActiveX Control Unspecified Remote Code Execution Vulnerabilities
Solution:
The vendor released an update to address this issue. Please see the references for details.
Solution:
The vendor released an update to address this issue. Please see the references for details.
References
Invensys Wonderware Info Server ActiveX Control Unspecified Remote Code Execution Vulnerabilities
References:
References:
- ICSA-11-195-01�??INVENSYS WONDERWARE INFORMATION SERVER (US-CERT)
- Wonderware Products Homepage (Invensys)