Lucene search

K
cveCertccCVE-2011-3330
HistoryNov 04, 2011 - 9:55 p.m.

CVE-2011-3330

2011-11-0421:55:03
CWE-119
certcc
web.nvd.nist.gov
40
cve-2011-3330
buffer overflow
unitelway
schneider electric
unity pro
opc factory server
vijeo citect
telemecanique
monitor pro
pl7 pro
arbitrary code execution
security vulnerability

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.006

Percentile

78.3%

Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers, to execute arbitrary code via an unspecified system parameter.

Affected configurations

Nvd
Node
schneider-electricmonitor_proRange7.6
OR
schneider-electricopc_factory_serverRange3.34
OR
schneider-electricpl7_proRange4.5sp5
OR
schneider-electrictelemecanique_driver_packRange2.6
OR
schneider-electricunity_proRange6.0
OR
schneider-electricvijeo_citectRange7.20
VendorProductVersionCPE
schneider-electricmonitor_pro*cpe:2.3:a:schneider-electric:monitor_pro:*:*:*:*:*:*:*:*
schneider-electricopc_factory_server*cpe:2.3:a:schneider-electric:opc_factory_server:*:*:*:*:*:*:*:*
schneider-electricpl7_pro*cpe:2.3:a:schneider-electric:pl7_pro:*:sp5:*:*:*:*:*:*
schneider-electrictelemecanique_driver_pack*cpe:2.3:a:schneider-electric:telemecanique_driver_pack:*:*:*:*:*:*:*:*
schneider-electricunity_pro*cpe:2.3:a:schneider-electric:unity_pro:*:*:*:*:*:*:*:*
schneider-electricvijeo_citect*cpe:2.3:a:schneider-electric:vijeo_citect:*:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.006

Percentile

78.3%

Related for CVE-2011-3330