CVE-2012-0258: Buffer Overflow
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the AddFile member.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0258?
CVE-2012-0258 has a critical severity rating due to its potential for remote code execution through a heap-based buffer overflow.
How do I fix CVE-2012-0258?
To fix CVE-2012-0258, users should update the affected Invensys software to the latest available versions that address this vulnerability.
What software is affected by CVE-2012-0258?
CVE-2012-0258 affects several Invensys products including Wonderware Application Server, Foxboro Control Software, and Wonderware Information Server versions up to specific limits.
What type of vulnerability is CVE-2012-0258?
CVE-2012-0258 is classified as a heap-based buffer overflow vulnerability.
Can CVE-2012-0258 be exploited remotely?
Yes, CVE-2012-0258 can be exploited remotely by attackers, allowing them to execute arbitrary code on the affected systems.