Certec atvise webMI2ADS Web Server Multiple Remote Vulnerabilities
BID:50048
Info
Certec atvise webMI2ADS Web Server Multiple Remote Vulnerabilities
| Bugtraq ID: | 50048 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-4880 CVE-2011-4881 CVE-2011-4882 CVE-2011-4883 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2011 12:00AM |
| Updated: | Apr 12 2012 01:50PM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
Certec atvise webMI2ADS 2.0 Certec atvise webMI2ADS 1.0 |
| Not Vulnerable: |
Certec atvise webMI2ADS 2.0.2 |
Discussion
Certec atvise webMI2ADS Web Server Multiple Remote Vulnerabilities
atvise webMI2ADS is prone to multiple remote vulnerabilities.
Exploiting these issues will allow an attacker to view arbitrary local files within the context of the webserver and crash the affected application, denying service to legitimate users. Information harvested may aid in launching further attacks.
atvise webMI2ADS 1.0 and prior versions are vulnerable.
atvise webMI2ADS is prone to multiple remote vulnerabilities.
Exploiting these issues will allow an attacker to view arbitrary local files within the context of the webserver and crash the affected application, denying service to legitimate users. Information harvested may aid in launching further attacks.
atvise webMI2ADS 1.0 and prior versions are vulnerable.
Exploit / POC
Certec atvise webMI2ADS Web Server Multiple Remote Vulnerabilities
An exploit is available. Please see the references for more information.
An exploit is available. Please see the references for more information.
Solution / Fix
Certec atvise webMI2ADS Web Server Multiple Remote Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Certec atvise webMI2ADS Web Server Multiple Remote Vulnerabilities
References:
References:
- atvise webMI2ADS Homepage (atvise)
- Vulnerabilities in atvise webMI2ADS 1.0 (SCADA) (Luigi Auriemma)
- ICSA-12-102-01�??CERTEC WEBMI2ADS MULTIPLE VULNERABILITIES (ICS-CERT)