Vulnerability Description
webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadwin | Webaccess | All versions |
Related Weaknesses (CWE)
References
- http://reversemode.com/index.php?option=com_content&task=view&id=72&Itemid=1Exploit
- http://www.reversemode.com/downloads/Scada_Trojans_Ruben_Rootedcon.pdf
- http://www.reversemode.com/downloads/exploit_advantech.zipExploit
- http://www.securityfocus.com/archive/1/517117
- http://www.securityfocus.com/bid/47008Exploit
- http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-081-01.pdf
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-094-02A.pdfUS Government Resource
- http://reversemode.com/index.php?option=com_content&task=view&id=72&Itemid=1Exploit
- http://www.reversemode.com/downloads/Scada_Trojans_Ruben_Rootedcon.pdf
- http://www.reversemode.com/downloads/exploit_advantech.zipExploit
- http://www.securityfocus.com/archive/1/517117
- http://www.securityfocus.com/bid/47008Exploit
- http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-081-01.pdf
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-094-02A.pdfUS Government Resource
FAQ
What is CVE-2011-4041?
CVE-2011-4041 is a vulnerability with a CVSS score of 10.0 (HIGH). webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592.
How severe is CVE-2011-4041?
CVE-2011-4041 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-4041?
Check the references section above for vendor advisories and patch information. Affected products include: Broadwin Webaccess.