Show plain JSON{"id": "CVE-2012-0257", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 6.8, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}]}, "published": "2012-04-02T20:55:02.187", "references": [{"url": "http://osvdb.org/80891", "source": "cret@cert.org"}, {"url": "http://secunia.com/advisories/48675", "source": "cret@cert.org"}, {"url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-081-01.pdf", "tags": ["US Government Resource"], "source": "cret@cert.org"}, {"url": "https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000071.pdf", "source": "cret@cert.org"}, {"url": "http://osvdb.org/80891", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://secunia.com/advisories/48675", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-081-01.pdf", "tags": ["US Government Resource"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000071.pdf", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-119"}]}], "descriptions": [{"lang": "en", "value": "Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the Open member, leading to a function-pointer overwrite."}, {"lang": "es", "value": "Desbordamiento de b\u00fafer basado en memoria din\u00e1mica en el componente ActiveX WWCabFile en Wonderware System Platform en Invensys Wonderware Application Server 2012 y anteriores, Foxboro Control Software v3.1 y anteriores, InFusion CE/FE/SCADA v2.5 y anteriores, Wonderware Information Server v4.5 y anteriores, ArchestrA Application Object Toolkit v3.2 y anteriores, y InTouch v10.0 hasta v10.5 ,permite a atacantes remotos ejecutar c\u00f3digo arbitrario a trav\u00e9s de una cadena larga sobre el miembro Open, provocando una sobrescritura de un puntero a funci\u00f3n."}], "lastModified": "2025-04-11T00:51:21.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:invensys:archestra_application_object_toolkit:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DCC6A67B-2844-4839-8CA2-C612C5B1EACB", "versionEndIncluding": "3.2"}, {"criteria": "cpe:2.3:a:invensys:foxboro_control_software:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F7F29DDE-04A2-462F-BA35-C1B27B9E96DF", "versionEndIncluding": "3.1"}, {"criteria": "cpe:2.3:a:invensys:infusion_control_edition:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FBBD076-515A-470F-9C29-A902C2042A24", "versionEndIncluding": "2.5"}, {"criteria": "cpe:2.3:a:invensys:infusion_foundation_edition:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4D10B2C8-CC92-491E-91F6-EAD96E878BE3", "versionEndIncluding": "2.5"}, {"criteria": "cpe:2.3:a:invensys:infusion_scada:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EAACC06C-4E8C-4E66-B007-E6BC9DAFEEAF", "versionEndIncluding": "2.5"}, {"criteria": "cpe:2.3:a:invensys:intouch:10.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3BDF7AED-4176-4EB8-8557-582BA29B63D2"}, {"criteria": "cpe:2.3:a:invensys:intouch:10.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF608404-2B0D-4FD1-9768-E984AE5F23D4"}, {"criteria": "cpe:2.3:a:invensys:wonderware_application_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "550932A9-9B6A-439A-A5A4-CAFB24DB28C8", "versionEndIncluding": "2012"}, {"criteria": "cpe:2.3:a:invensys:wonderware_information_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C4265378-CF22-42AC-B63C-73F96507E680", "versionEndIncluding": "4.5"}, {"criteria": "cpe:2.3:a:invensys:wonderware_information_server:3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "262CBEB8-A6EA-48DE-B5A5-460660F33442"}, {"criteria": "cpe:2.3:a:invensys:wonderware_information_server:4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FC154F44-2618-4AD5-B252-98E521F98CEB"}, {"criteria": "cpe:2.3:a:invensys:wonderware_information_server:4.0:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "325DE4D6-7649-4566-BC6E-1F8DC16FF1A9"}], "operator": "OR"}]}], "sourceIdentifier": "cret@cert.org"}