First published: Mon Dec 05 2011(Updated: )
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and process control.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
InduSoft Web Studio | =6.1 | |
InduSoft Web Studio | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-4051 is classified as high due to the potential for remote code execution.
To fix CVE-2011-4051, it is recommended to apply the latest patches from InduSoft for Web Studio versions 6.1 and 7.0.
CVE-2011-4051 can allow remote attackers to execute arbitrary code on affected systems without authentication.
InduSoft Web Studio versions 6.1 and 7.0 are affected by CVE-2011-4051.
No, CVE-2011-4051 does not require authentication, making it easier for attackers to exploit.