CVE-2011-4055

Buffer overflow in the WebClient ActiveX control in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to execute arbitrary code via a long string in a parameter associated with the location URL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:tecnomatix_factorylink:6.6.1:*:*:*:*:*:*:*
cpe:2.3:a:siemens:tecnomatix_factorylink:7.5.217:*:*:*:*:*:*:*
cpe:2.3:a:siemens:tecnomatix_factorylink:8.0.2.54:*:*:*:*:*:*:*

History

21 Nov 2024, 01:31

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/51266 - () http://www.securityfocus.com/bid/51266 -
References () http://www.us-cert.gov/control_systems/pdf/ICSA-11-343-01.pdf - US Government Resource () http://www.us-cert.gov/control_systems/pdf/ICSA-11-343-01.pdf - US Government Resource
References () http://www.usdata.com/sea/factorylink/en/p_nav5.asp - Patch, Vendor Advisory () http://www.usdata.com/sea/factorylink/en/p_nav5.asp - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/72117 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/72117 -

Information

Published : 2012-01-08 00:55

Updated : 2025-04-11 00:51


NVD link : CVE-2011-4055

Mitre link : CVE-2011-4055

CVE.ORG link : CVE-2011-4055


JSON object : View

Products Affected

siemens

  • tecnomatix_factorylink
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer