First published: Fri Jul 29 2011(Updated: )
Multiple stack-based buffer overflows in Invensys Wonderware Information Server 3.1, 4.0, and 4.0 SP1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via two unspecified ActiveX controls.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invensys Wonderware Information Server | =4.0-sp1 | |
Invensys Wonderware Information Server | =3.1 | |
Invensys Wonderware Information Server | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2962 has a medium severity rating due to its potential for denial of service and possible remote code execution.
To mitigate CVE-2011-2962, users should apply the latest patches and updates provided by Invensys for the affected Wonderware Information Server versions.
CVE-2011-2962 affects Invensys Wonderware Information Server versions 3.1, 4.0, and 4.0 SP1.
CVE-2011-2962 can enable remote attackers to execute arbitrary code and cause denial of service through stack-based buffer overflows.
Currently, there are no specific workarounds for CVE-2011-2962, so it is recommended to apply relevant patches as soon as they are available.