CVE-2011-4034
high · 9.3Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.
9.3
CVSS
13.4%
EPSS (exploit prob.)
96th
EPSS percentile
2011-12-02
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| schneider-electric | vijeo_historian | <= 4.30 |
| schneider-electric | vijeo_historian | 4.0 |
| schneider-electric | vijeo_historian | 4.10 |
| schneider-electric | vijeo_historian | 4.20 |
| schneider-electric | citecthistorian | <= 4.30 |
| schneider-electric | citecthistorian | 4.20 |
| schneider-electric | citectscada_reports | <= 4.10 |
| schneider-electric | citectscada_reports | 4.0 |
Check a specific version with /api/v1/cve/match.
References
- http://www.citect.com/index.php?option=com_content&view=article&id=1656&Itemid=1695
- http://www.scada.schneider-electric.com/sites/scada/en/login/historian-vulnerability.page
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-307-01.pdf
- http://www.citect.com/index.php?option=com_content&view=article&id=1656&Itemid=1695
- http://www.scada.schneider-electric.com/sites/scada/en/login/historian-vulnerability.page
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-307-01.pdf
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-4034