CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
97.5%
Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsystem in ICONICS BizViz 9.x before 9.22 and GENESIS32 9.x before 9.22 allows remote attackers to execute arbitrary code via a long string in the argument. NOTE: some of these details are obtained from third party information.
Vendor | Product | Version | CPE |
---|---|---|---|
iconics | bizviz | 9.0 | cpe:2.3:a:iconics:bizviz:9.0:*:*:*:*:*:*:* |
iconics | bizviz | 9.01 | cpe:2.3:a:iconics:bizviz:9.01:*:*:*:*:*:*:* |
iconics | bizviz | 9.1 | cpe:2.3:a:iconics:bizviz:9.1:*:*:*:*:*:*:* |
iconics | bizviz | 9.2 | cpe:2.3:a:iconics:bizviz:9.2:*:*:*:*:*:*:* |
iconics | bizviz | 9.13 | cpe:2.3:a:iconics:bizviz:9.13:*:*:*:*:*:*:* |
iconics | bizviz | 9.20 | cpe:2.3:a:iconics:bizviz:9.20:*:*:*:*:*:*:* |
iconics | bizviz | 9.21 | cpe:2.3:a:iconics:bizviz:9.21:*:*:*:*:*:*:* |
iconics | genesis32 | 9.0 | cpe:2.3:a:iconics:genesis32:9.0:*:*:*:*:*:*:* |
iconics | genesis32 | 9.1 | cpe:2.3:a:iconics:genesis32:9.1:*:*:*:*:*:*:* |
iconics | genesis32 | 9.01 | cpe:2.3:a:iconics:genesis32:9.01:*:*:*:*:*:*:* |
secunia.com/advisories/44417
www.exploit-db.com/exploits/17240
www.exploit-db.com/exploits/17269
www.osvdb.org/72135
www.security-assessment.com/files/documents/advisory/ICONICS_WebHMI.pdf
www.securityfocus.com/bid/47704
www.us-cert.gov/control_systems/pdf/ICSA-11-131-01.pdf
www.vupen.com/english/advisories/2011/1174
exchange.xforce.ibmcloud.com/vulnerabilities/67267