Lucene search

K
cveCertccCVE-2013-0108
HistoryFeb 24, 2013 - 11:48 a.m.

CVE-2013-0108

2013-02-2411:48:21
CWE-94
certcc
web.nvd.nist.gov
44
activex control
hscremotedeploy.dll
honeywell ebi
symmetre
remote code execution
html document
security vulnerability
cve-2013-0108

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.911

Percentile

98.9%

An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1, and R410.2; ComfortPoint Open Manager (aka CPO-M) Station R100; and HMIWeb Browser client packages allows remote attackers to execute arbitrary code via a crafted HTML document.

Affected configurations

Nvd
Node
honeywellenterprise_buildings_integratorMatchr310
OR
honeywellenterprise_buildings_integratorMatchr400.2
OR
honeywellenterprise_buildings_integratorMatchr410.1
OR
honeywellenterprise_buildings_integratorMatchr410.2
Node
honeywellsymmetreMatchr310
OR
honeywellsymmetreMatchr400.2
OR
honeywellsymmetreMatchr410.1
Node
honeywellcomfortpoint_open_manager_stationMatchr100
VendorProductVersionCPE
honeywellenterprise_buildings_integratorr310cpe:2.3:a:honeywell:enterprise_buildings_integrator:r310:*:*:*:*:*:*:*
honeywellenterprise_buildings_integratorr400.2cpe:2.3:a:honeywell:enterprise_buildings_integrator:r400.2:*:*:*:*:*:*:*
honeywellenterprise_buildings_integratorr410.1cpe:2.3:a:honeywell:enterprise_buildings_integrator:r410.1:*:*:*:*:*:*:*
honeywellenterprise_buildings_integratorr410.2cpe:2.3:a:honeywell:enterprise_buildings_integrator:r410.2:*:*:*:*:*:*:*
honeywellsymmetrer310cpe:2.3:a:honeywell:symmetre:r310:*:*:*:*:*:*:*
honeywellsymmetrer400.2cpe:2.3:a:honeywell:symmetre:r400.2:*:*:*:*:*:*:*
honeywellsymmetrer410.1cpe:2.3:a:honeywell:symmetre:r410.1:*:*:*:*:*:*:*
honeywellcomfortpoint_open_manager_stationr100cpe:2.3:a:honeywell:comfortpoint_open_manager_station:r100:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.911

Percentile

98.9%