Lucene search

K
cveMitreCVE-2011-5088
HistoryApr 18, 2012 - 5:55 p.m.

CVE-2011-5088

2012-04-1817:55:01
mitre
web.nvd.nist.gov
21
cve-2011-5088
genesis32
icosetserver
activex
iconics
bizviz
remote code execution
security vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

High

EPSS

0.007

Percentile

80.9%

The GENESIS32 IcoSetServer ActiveX control in ICONICS GENESIS32 9.21 and BizViz 9.21 configures the trusted zone on the basis of user input, which allows remote attackers to execute arbitrary code via a crafted web site, related to a “Workbench32/WebHMI component SetTrustedZone Policy vulnerability.”

Affected configurations

Nvd
Node
iconicsbizvizMatch9.21
OR
iconicsgenesis32Match9.21
VendorProductVersionCPE
iconicsbizviz9.21cpe:2.3:a:iconics:bizviz:9.21:*:*:*:*:*:*:*
iconicsgenesis329.21cpe:2.3:a:iconics:genesis32:9.21:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

High

EPSS

0.007

Percentile

80.9%

Related for CVE-2011-5088