HIGH · 9.3

CVE-2010-2974

Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control in Wonderware Application Server (WAS) before 3.1 SP...

Vulnerability Description

Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control in Wonderware Application Server (WAS) before 3.1 SP2 P01, as used in the Wonderware Archestra Integrated Development Environment (IDE) and the InFusion Integrated Engineering Environment (IEE), allows remote attackers to execute arbitrary code via the first argument to the UnsubscribeData method.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
InvensysWonderware Archestra Configuration Access Component Activex ControlAll versions
InvensysInfusion Integrated Engineering EnvironmentAll versions
InvensysWonderware Application Server<= 3.1
InvensysWonderware Archestra Integrated Development EnvironmentAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-2974?

CVE-2010-2974 is a vulnerability with a CVSS score of 9.3 (HIGH). Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control in Wonderware Application Server (WAS) before 3.1 SP...

How severe is CVE-2010-2974?

CVE-2010-2974 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-2974?

Check the references section above for vendor advisories and patch information. Affected products include: Invensys Wonderware Archestra Configuration Access Component Activex Control, Invensys Infusion Integrated Engineering Environment, Invensys Wonderware Application Server, Invensys Wonderware Archestra Integrated Development Environment.