CVE-2007-4473
Estado: ModificadaAlta (10)—
Gesytec Easylon OPC Server before 2.3.44 does not properly validate server handles, which allows remote attackers to execute arbitrary code or cause a denial of service via unspecified network traffic to the OLE for Process Control (OPC) interface, probably related to free operations on arbitrary memory addresses through certain Remove functions, and read and write operations on arbitrary memory addresses through certain Set, Read, and Write functions.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.69%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-119
Referencias
- http://osvdb.org/42650
- http://secunia.com/advisories/28079
- http://www.kb.cert.org/vuls/id/205073
- http://www.neutralbit.com/downloads/NB-NB-001-EXT-OPC%20Security%20Testing.pdf
- http://www.neutralbit.com/en/rd/opctest/
- http://www.securityfocus.com/bid/26876
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39062
- http://osvdb.org/42650
- http://secunia.com/advisories/28079
- http://www.kb.cert.org/vuls/id/205073
- http://www.neutralbit.com/downloads/NB-NB-001-EXT-OPC%20Security%20Testing.pdf
- http://www.neutralbit.com/en/rd/opctest/
- http://www.securityfocus.com/bid/26876
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39062
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-4473",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-12-17T21:46:00.000",
"references": [
{
"url": "http://osvdb.org/42650",
"source": "cret@cert.org"
},
{
"url": "http://secunia.com/advisories/28079",
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/205073",
"tags": [
"Patch",
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.neutralbit.com/downloads/NB-NB-001-EXT-OPC%20Security%20Testing.pdf",
"source": "cret@cert.org"
},
{
"url": "http://www.neutralbit.com/en/rd/opctest/",
"source": "cret@cert.org"
},
{
"url": "http://www.securityfocus.com/bid/26876",
"source": "cret@cert.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39062",
"source": "cret@cert.org"
},
{
"url": "http://osvdb.org/42650",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28079",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/205073",
"tags": [
"Patch",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.neutralbit.com/downloads/NB-NB-001-EXT-OPC%20Security%20Testing.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.neutralbit.com/en/rd/opctest/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/26876",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39062",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Gesytec Easylon OPC Server before 2.3.44 does not properly validate server handles, which allows remote attackers to execute arbitrary code or cause a denial of service via unspecified network traffic to the OLE for Process Control (OPC) interface, probably related to free operations on arbitrary memory addresses through certain Remove functions, and read and write operations on arbitrary memory addresses through certain Set, Read, and Write functions."
},
{
"lang": "es",
"value": "Gesytec Easylon OPC Server anterior a 2.3.44 no valida adecuadamente manejadores de servidor, lo cual permite a atacantes remotos ejecutar código de su elección o provocar denegación de servicio a través de un tráfico de red específico en el OLE para las interfaces Process Control (OPC), probablemente relacionado con operaciones libres sobre direcciones de memoria de su elección a través de ciertas funciones Remove, y leer y escribir operaciones sobre direcciones de memoria de su elección a través de ciertas funciones para asignar, leer y escribir."
}
],
"lastModified": "2026-06-16T22:44:09.850",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gesytec_easylon:opc_server:2.30.32:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "213D3C21-4A3D-411B-B557-5D3C96B6049B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}