CVE-2012-0258
Estado: ModificadaMedia (6.8)—
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the AddFile member.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.16%
- Percentil entre todas las CVEs puntuadas: 88
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (8)
CWE
- CWE-119
Referencias
- http://osvdb.org/80891
- http://secunia.com/advisories/48675
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-081-01.pdf
- https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000071.pdf
- http://osvdb.org/80891
- http://secunia.com/advisories/48675
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-081-01.pdf
- https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000071.pdf
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-0258",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-04-02T20:55:02.230",
"references": [
{
"url": "http://osvdb.org/80891",
"source": "cret@cert.org"
},
{
"url": "http://secunia.com/advisories/48675",
"source": "cret@cert.org"
},
{
"url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-081-01.pdf",
"tags": [
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000071.pdf",
"source": "cret@cert.org"
},
{
"url": "http://osvdb.org/80891",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/48675",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-081-01.pdf",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000071.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the AddFile member."
},
{
"lang": "es",
"value": "Desbordamiento de búfer basado en memoria dinámica en el componente ActiveX WWCabFile en Wonderware System Platform en Invensys Wonderware Application Server 2012 y anteriores, Foxboro Control Software v3.1 y anteriores, InFusion CE/FE/SCADA v2.5 y anteriores, Wonderware Information Server v4.5 y anteriores, ArchestrA Application Object Toolkit v3.2 y anteriores, y InTouch v10.0 hasta v10.5 ,permite a atacantes remotos ejecutar código arbitrario a través de una cadena larga sobre el miembro Addfile."
}
],
"lastModified": "2026-06-16T23:37:00.033",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:invensys:archestra_application_object_toolkit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DCC6A67B-2844-4839-8CA2-C612C5B1EACB",
"versionEndIncluding": "3.2"
},
{
"criteria": "cpe:2.3:a:invensys:foxboro_control_software:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7F29DDE-04A2-462F-BA35-C1B27B9E96DF",
"versionEndIncluding": "3.1"
},
{
"criteria": "cpe:2.3:a:invensys:infusion_control_edition:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3FBBD076-515A-470F-9C29-A902C2042A24",
"versionEndIncluding": "2.5"
},
{
"criteria": "cpe:2.3:a:invensys:infusion_foundation_edition:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D10B2C8-CC92-491E-91F6-EAD96E878BE3",
"versionEndIncluding": "2.5"
},
{
"criteria": "cpe:2.3:a:invensys:infusion_scada:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EAACC06C-4E8C-4E66-B007-E6BC9DAFEEAF",
"versionEndIncluding": "2.5"
},
{
"criteria": "cpe:2.3:a:invensys:intouch:10.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3BDF7AED-4176-4EB8-8557-582BA29B63D2"
},
{
"criteria": "cpe:2.3:a:invensys:intouch:10.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF608404-2B0D-4FD1-9768-E984AE5F23D4"
},
{
"criteria": "cpe:2.3:a:invensys:wonderware_application_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "550932A9-9B6A-439A-A5A4-CAFB24DB28C8",
"versionEndIncluding": "2012"
},
{
"criteria": "cpe:2.3:a:invensys:wonderware_information_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4265378-CF22-42AC-B63C-73F96507E680",
"versionEndIncluding": "4.5"
},
{
"criteria": "cpe:2.3:a:invensys:wonderware_information_server:3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "262CBEB8-A6EA-48DE-B5A5-460660F33442"
},
{
"criteria": "cpe:2.3:a:invensys:wonderware_information_server:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC154F44-2618-4AD5-B252-98E521F98CEB"
},
{
"criteria": "cpe:2.3:a:invensys:wonderware_information_server:4.0:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "325DE4D6-7649-4566-BC6E-1F8DC16FF1A9"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}