Lucene search

K
nvd[email protected]NVD:CVE-2011-5088
HistoryApr 18, 2012 - 5:55 p.m.

CVE-2011-5088

2012-04-1817:55:01
web.nvd.nist.gov
1

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

High

EPSS

0.007

Percentile

80.9%

The GENESIS32 IcoSetServer ActiveX control in ICONICS GENESIS32 9.21 and BizViz 9.21 configures the trusted zone on the basis of user input, which allows remote attackers to execute arbitrary code via a crafted web site, related to a “Workbench32/WebHMI component SetTrustedZone Policy vulnerability.”

Affected configurations

Nvd
Node
iconicsbizvizMatch9.21
OR
iconicsgenesis32Match9.21
VendorProductVersionCPE
iconicsbizviz9.21cpe:2.3:a:iconics:bizviz:9.21:*:*:*:*:*:*:*
iconicsgenesis329.21cpe:2.3:a:iconics:genesis32:9.21:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

High

EPSS

0.007

Percentile

80.9%

Related for NVD:CVE-2011-5088