First published: Fri Dec 02 2011(Updated: )
Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Vijeo Historian | =4.20 | |
Schneider-electric Vijeo Historian | =4.0 | |
Schneider-electric Vijeo Historian | =4.10 | |
Schneider-electric Vijeo Historian | <=4.30 | |
Schneider-electric Citecthistorian | <=4.30 | |
Schneider-electric Citecthistorian | =4.20 | |
Schneider-electric Citectscada Reports | <=4.10 | |
Schneider-electric Citectscada Reports | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4036 is classified as a high severity vulnerability due to its ability to allow remote attackers to read arbitrary files.
To fix CVE-2011-4036, users should upgrade to the latest versions of Schneider Electric Vijeo Historian, CitectHistorian, and CitectSCADA Reports that are not affected by this vulnerability.
CVE-2011-4036 affects Schneider Electric Vijeo Historian versions up to 4.30, CitectHistorian versions up to 4.30, and CitectSCADA Reports versions up to 4.10.
CVE-2011-4036 can be exploited through directory traversal attacks, allowing attackers to access sensitive files on the server.
Yes, CVE-2011-4036 specifically affects Schneider Electric's Vijeo Historian, CitectHistorian, and CitectSCADA Reports software.