PT-2011-3475 · Ge Intelligent Platforms · Proficy Applications
Published
2011-11-02
·
Updated
2011-11-17
·
CVE-2011-1919
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GE Intelligent Platforms Proficy Applications versions prior to 4.4.1 SIM 101
GE Intelligent Platforms Proficy Applications versions 5.x prior to 5.0 SIM 43
Description
The issue is related to multiple stack-based buffer overflows that can be triggered by remote attackers via crafted TCP message traffic. This can lead to a denial of service, causing the daemon to crash, or potentially allow the execution of arbitrary code. The affected components include
PRProficyMgr.exe in Proficy Server Manager, PRGateway.exe in Proficy Server Gateway, PRRDS.exe in Proficy Remote Data Service, and PRLicenseMgr.exe in Proficy Server License Manager.Recommendations
For GE Intelligent Platforms Proficy Applications versions prior to 4.4.1 SIM 101, update to version 4.4.1 SIM 101 or later.
For GE Intelligent Platforms Proficy Applications versions 5.x prior to 5.0 SIM 43, update to version 5.0 SIM 43 or later.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Proficy Applications