Lucene search

K
nvd[email protected]NVD:CVE-2011-3330
HistoryNov 04, 2011 - 9:55 p.m.

CVE-2011-3330

2011-11-0421:55:03
CWE-119
web.nvd.nist.gov
3

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

High

EPSS

0.006

Percentile

78.3%

Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers, to execute arbitrary code via an unspecified system parameter.

Affected configurations

Nvd
Node
schneider-electricmonitor_proRange7.6
OR
schneider-electricopc_factory_serverRange3.34
OR
schneider-electricpl7_proRange4.5sp5
OR
schneider-electrictelemecanique_driver_packRange2.6
OR
schneider-electricunity_proRange6.0
OR
schneider-electricvijeo_citectRange7.20
VendorProductVersionCPE
schneider-electricmonitor_pro*cpe:2.3:a:schneider-electric:monitor_pro:*:*:*:*:*:*:*:*
schneider-electricopc_factory_server*cpe:2.3:a:schneider-electric:opc_factory_server:*:*:*:*:*:*:*:*
schneider-electricpl7_pro*cpe:2.3:a:schneider-electric:pl7_pro:*:sp5:*:*:*:*:*:*
schneider-electrictelemecanique_driver_pack*cpe:2.3:a:schneider-electric:telemecanique_driver_pack:*:*:*:*:*:*:*:*
schneider-electricunity_pro*cpe:2.3:a:schneider-electric:unity_pro:*:*:*:*:*:*:*:*
schneider-electricvijeo_citect*cpe:2.3:a:schneider-electric:vijeo_citect:*:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

High

EPSS

0.006

Percentile

78.3%

Related for NVD:CVE-2011-3330