First published: Thu Mar 15 2012(Updated: )
PRLicenseMgr.exe in the Proficy Server License Manager in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted TCP session on port 12401.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
GE Intelligent Platforms Proficy Plant Applications | <=5.0 | |
GE Intelligent Platforms Proficy Plant Applications | =4.2.2 | |
GE Intelligent Platforms Proficy Plant Applications | =4.2.3 | |
GE Intelligent Platforms Proficy Plant Applications | =4.3.1 | |
GE Intelligent Platforms Proficy Plant Applications | =4.4.1 | |
GE Intelligent Platforms Proficy Plant Applications | =215.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0231 is classified as a high severity vulnerability due to its potential for remote denial of service and arbitrary code execution.
To fix CVE-2012-0231, it is recommended to upgrade to a version of Proficy Plant Applications greater than 5.0 that addresses this vulnerability.
The impact of CVE-2012-0231 includes potential memory corruption and the possibility for an attacker to execute arbitrary code on affected systems.
CVE-2012-0231 affects GE Intelligent Platforms Proficy Plant Applications version 5.0 and earlier.
Yes, CVE-2012-0231 can be exploited through a crafted TCP session targeting port 12401.