CVE-2010-2974
Estado: ModificadaAlta (9.3)—
Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control in Wonderware Application Server (WAS) before 3.1 SP2 P01, as used in the Wonderware Archestra Integrated Development Environment (IDE) and the InFusion Integrated Engineering Environment (IEE), allows remote attackers to execute arbitrary code via the first argument to the UnsubscribeData method.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.48%
- Percentil entre todas las CVEs puntuadas: 91
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-119
Referencias
- http://www.kb.cert.org/vuls/id/703189
- http://www.kb.cert.org/vuls/id/MORO-87MHPT
- http://www.pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsID=203108
- https://wdnresource.wonderware.com/support/kbcd/html/1/t002492.htm
- http://www.kb.cert.org/vuls/id/703189
- http://www.kb.cert.org/vuls/id/MORO-87MHPT
- http://www.pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsID=203108
- https://wdnresource.wonderware.com/support/kbcd/html/1/t002492.htm
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-2974",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-08-05T19:17:55.543",
"references": [
{
"url": "http://www.kb.cert.org/vuls/id/703189",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/MORO-87MHPT",
"source": "cve@mitre.org"
},
{
"url": "http://www.pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsID=203108",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://wdnresource.wonderware.com/support/kbcd/html/1/t002492.htm",
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/703189",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/MORO-87MHPT",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsID=203108",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wdnresource.wonderware.com/support/kbcd/html/1/t002492.htm",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control in Wonderware Application Server (WAS) before 3.1 SP2 P01, as used in the Wonderware Archestra Integrated Development Environment (IDE) and the InFusion Integrated Engineering Environment (IEE), allows remote attackers to execute arbitrary code via the first argument to the UnsubscribeData method."
},
{
"lang": "es",
"value": "Desbordamiento de búfer basado en pila en la interfaz IConfigurationAccess en el control ActiveX Invensys Wonderware Archestra ConfigurationAccessComponent de Wonderware Application Server (WAS) anterior a v3.1 SP2 P01, como el usado en el Wonderware Archestra Integrated Development Environment (IDE) y el InFusion Integrated Engineering Environment (IEE), permite a los atacantes remotos ejecutar código a su elección a través del primer argumento del método UnsubscribeData."
}
],
"lastModified": "2026-06-16T23:21:52.143",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:invensys:wonderware_archestra_configuration_access_component_activex_control:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B08B61E8-62EF-46B0-8881-300A02E911F5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:invensys:infusion_integrated_engineering_environment:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9294B6B1-7D7C-461B-ADC1-D90251FADB96"
},
{
"criteria": "cpe:2.3:a:invensys:wonderware_application_server:*:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C53D322C-1D42-479E-9225-40684655F4CA",
"versionEndIncluding": "3.1"
},
{
"criteria": "cpe:2.3:a:invensys:wonderware_application_server:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "68FA27FB-6AA3-4E6F-83EB-066DAF0BD3A8"
},
{
"criteria": "cpe:2.3:a:invensys:wonderware_application_server:2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B64216A-3D05-4384-8B35-845974B99128"
},
{
"criteria": "cpe:2.3:a:invensys:wonderware_application_server:3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5EA5956-AFFF-4AF6-8E51-60B702E4E3FD"
},
{
"criteria": "cpe:2.3:a:invensys:wonderware_application_server:3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA9909E3-C0C3-4EE8-A592-948D8F90E569"
},
{
"criteria": "cpe:2.3:a:invensys:wonderware_application_server:3.1:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2576F8F1-DA43-47E1-95D9-9A9233FCD2B0"
},
{
"criteria": "cpe:2.3:a:invensys:wonderware_archestra_integrated_development_environment:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7C0CE9E0-61A4-4D92-BB3F-4437E77E27CE"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org",
"evaluatorSolution": "Per: http://www.kb.cert.org/vuls/id/703189\r\n\r\n'According to Invensys, users that are using IAS 2.1 (all versions)-IDE, WAS 3.0 (all versions)-IDE, WAS 3.1 (all versions)-IDE, InFusion CE 2.0-IEE, InFusion FE 1.0 (all versions)-IEE, InFusion FE 2.0-IEE, InFusion SCADA 2.0–IEE should apply the vendor security update. This vulnerability is not present in Wonderware Application Server 3.1 Service Pack 2 Patch 01 (WAS 3.1 SP2 P01).'"
}