CVE-2012-4700
critical
CVSS v3
—
CVSS v2
9.3
VIR risk
9.3
Description
Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attackers to execute arbitrary code via a crafted HTML document.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: ics-cert@hq.dhs.gov — http://www.integraxor.com/blog/security-issue-for-activex-enabled-browser-vulnerability-note
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ecava | integraxor | {"endIncluding":"4.00"} | |
| ecava | integraxor | 3.71 | |
| ecava | integraxor | 3.72 | |
References
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.