Vulnerability Description
Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attackers to execute arbitrary code via a crafted HTML document.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ecava | Integraxor | <= 4.00 |
Related Weaknesses (CWE)
References
- http://ics-cert.us-cert.gov/pdf/ICSA-13-036-02.pdfUS Government Resource
- http://www.integraxor.com/blog/security-issue-for-activex-enabled-browser-vulnerPatchVendor Advisory
- http://ics-cert.us-cert.gov/pdf/ICSA-13-036-02.pdfUS Government Resource
- http://www.integraxor.com/blog/security-issue-for-activex-enabled-browser-vulnerPatchVendor Advisory
FAQ
What is CVE-2012-4700?
CVE-2012-4700 is a vulnerability with a CVSS score of 9.3 (HIGH). Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attackers to execute arbitrary code via a crafted HTML document.
How severe is CVE-2012-4700?
CVE-2012-4700 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4700?
Check the references section above for vendor advisories and patch information. Affected products include: Ecava Integraxor.