First published: Fri Feb 10 2012(Updated: )
Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access violation."
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invensys Wonderware HMI Reports | <=3.42.835.0304 | |
Dreamreport Remote Connector | =3.41 | |
Dreamreport Remote Connector | <=3.43 | |
Dreamreport Remote Connector | =3.21 | |
Dreamreport Remote Connector | =3.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4039 is classified as a critical vulnerability due to its potential to allow remote code execution.
To mitigate CVE-2011-4039, upgrade Invensys Wonderware HMI Reports and Ocean Data Systems Dream Report to versions that are not affected by this vulnerability.
CVE-2011-4039 affects Invensys Wonderware HMI Reports up to version 3.42.835.0304 and Ocean Data Systems Dream Report versions 3.21, 3.41, 3.42, and earlier.
Yes, CVE-2011-4039 can be exploited remotely if a user assists the attacker by opening a specially crafted file.
CVE-2011-4039 is categorized as a remote code execution vulnerability.