Lucene search

K
cve[email protected]CVE-2011-2386
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2011-2386

2022-10-0316:15:16
CWE-94
web.nvd.nist.gov
26
cve
visiwavereport.exe
azo technologies
inc
visiwave site survey
code execution
remote attackers
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.91 High

EPSS

Percentile

98.9%

VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary code via a (1) vws and (2) vwr file with an invalid Type property, which triggers an untrusted pointer dereference.

Affected configurations

NVD
Node
visiwavesite_surveyRange2.1
OR
visiwavesite_surveyMatch1.6.12
OR
visiwavesite_surveyMatch2.0.12

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.91 High

EPSS

Percentile

98.9%