PT-2014-2638 · Wellintech · Kingalarm&Event+2

Andrea Micalizzi

·

Publicado

2014-01-15

·

Atualizado

2014-02-05

·

CVE-2013-2827

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WellinTech KingSCADA versions prior to 3.1.2 WellinTech KingAlarm&Event versions prior to 3.1 WellinTech KingGraphic versions prior to 3.1.2
Description The issue allows remote attackers to download arbitrary DLL code onto a client machine and execute this code via the ProjectURL property value. This is due to an unspecified ActiveX control in the affected software.
Recommendations For WellinTech KingSCADA versions prior to 3.1.2, update to version 3.1.2 or later. For WellinTech KingAlarm&Event versions prior to 3.1, update to version 3.1 or later. For WellinTech KingGraphic versions prior to 3.1.2, update to version 3.1.2 or later.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-2827
ZDI-14-011

Produtos afetados

Kingalarm&Event
Kinggraphic
Kingscada