Lucene search

K
cve[email protected]CVE-2010-2974
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-2974

2022-10-0316:21:09
CWE-119
web.nvd.nist.gov
28
cve-2010-2974
stack-based buffer overflow
iconfigurationaccess
invensys wonderware
activex control
wonderware application server
remote code execution
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.4 High

AI Score

Confidence

High

0.025 Low

EPSS

Percentile

90.2%

Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control in Wonderware Application Server (WAS) before 3.1 SP2 P01, as used in the Wonderware Archestra Integrated Development Environment (IDE) and the InFusion Integrated Engineering Environment (IEE), allows remote attackers to execute arbitrary code via the first argument to the UnsubscribeData method.

Affected configurations

NVD
Node
invensyswonderware_archestra_configuration_access_component_activex_control
AND
invensysinfusion_integrated_engineering_environment
OR
invensyswonderware_application_serverRange3.1sp2
OR
invensyswonderware_application_serverMatch2.0
OR
invensyswonderware_application_serverMatch2.1
OR
invensyswonderware_application_serverMatch3.0
OR
invensyswonderware_application_serverMatch3.1
OR
invensyswonderware_application_serverMatch3.1sp1
OR
invensyswonderware_archestra_integrated_development_environment

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.4 High

AI Score

Confidence

High

0.025 Low

EPSS

Percentile

90.2%

Related for CVE-2010-2974