CVE-2012-0229

critical
Published 2012-03-15 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

The Data Archiver service in GE Intelligent Platforms Proficy Historian 4.5 and earlier allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted session on TCP port 14000 to (1) ihDataArchiver.exe or (2) ihDataArchiver_x64.exe.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cret@cert.org — http://support.ge-ip.com/support/index?page=kbchannel&id=S:KB14767

Application impact

VendorProductVersionsFixed
geintelligent_platforms_proficy_historian{"endIncluding":"4.5"}
geintelligent_platforms_proficy_historian1.0
geintelligent_platforms_proficy_historian2.0
geintelligent_platforms_proficy_historian3.0
geintelligent_platforms_proficy_historian3.1
geintelligent_platforms_proficy_historian3.5
geintelligent_platforms_proficy_historian4.0

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.