First published: Thu Mar 15 2012(Updated: )
The Data Archiver service in GE Intelligent Platforms Proficy Historian 4.5 and earlier allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted session on TCP port 14000 to (1) ihDataArchiver.exe or (2) ihDataArchiver_x64.exe.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
GE Proficy Historian | <=4.5 | |
GE Proficy Historian | =1.0 | |
GE Proficy Historian | =2.0 | |
GE Proficy Historian | =2.0-beta | |
GE Proficy Historian | =3.0 | |
GE Proficy Historian | =3.1 | |
GE Proficy Historian | =3.5 | |
GE Proficy Historian | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0229 has been classified as critical due to its potential to cause denial of service and execute arbitrary code.
To fix CVE-2012-0229, update GE Intelligent Platforms Proficy Historian to a version beyond 4.5.
CVE-2012-0229 affects GE Intelligent Platforms Proficy Historian versions 4.5 and earlier, including all versions from 1.0 through 4.5.
Yes, CVE-2012-0229 can cause memory corruption which may lead to data loss or corruption.
CVE-2012-0229 exploits a vulnerability in the Data Archiver service that allows crafted sessions on TCP port 14000.