« Volver al listado

CVE-2011-0340

Estado: ModificadaAlta (9.3)—

Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-0340",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "PSIRT-CNA@flexerasoftware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-05-04T22:55:01.467",
  "references": [
    {
      "url": "http://ics-cert.us-cert.gov/advisories/ICSA-12-249-03",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://secunia.com/advisories/42928",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://secunia.com/advisories/43116",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://secunia.com/secunia_research/2011-36/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://secunia.com/secunia_research/2011-37/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.advantechdirect.com/eMarketingPrograms/AStudio_Patch/AStudio7.0_Patch_Final.htm",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.indusoft.com/hotfixes/hotfixes.php",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/47596",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-137-02.pdf",
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/1115",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/1116",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT-CNA@flexerasoftware.com"
    },
    {
      "url": "http://ics-cert.us-cert.gov/advisories/ICSA-12-249-03",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/42928",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/43116",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/secunia_research/2011-36/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/secunia_research/2011-37/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.advantechdirect.com/eMarketingPrograms/AStudio_Patch/AStudio7.0_Patch_Final.htm",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.indusoft.com/hotfixes/hotfixes.php",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/47596",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-137-02.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/1115",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/1116",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method."
    },
    {
      "lang": "es",
      "value": "Múltiples desbordamientos de buffer en el control ActiveX ISSymbol de ISSymbol.ocx 61.6.0.0 y 301.1009.2904.0 de la máquina virtual ISSymbol, como se ha distribuído en Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio anteriores a 7.0+SP1, y InduSoft Thin Client 7.0. Permite a atacantes remotos ejecutar código de su elección a través de los valores de propiedades extensos (1) InternationalOrder, (2) InternationalSeparator, o (3) LogFileName; o (4) un argumento bstrFileName extenso al método OpenScreen."
    }
  ],
  "lastModified": "2026-06-16T23:27:12.117",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:advantech:advantech_studio:6.1:sp6_61.6.01.05:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D2F2836-EF2C-4110-8740-0F32957B0FCA"
            },
            {
              "criteria": "cpe:2.3:a:indusoft:thin_client:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26902C28-F3E8-488D-B8F5-4A1E8C731FC7"
            },
            {
              "criteria": "cpe:2.3:a:indusoft:web_studio:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E16C750-58D3-4BED-AB96-52B7365ED5C2",
              "versionEndIncluding": "7.0"
            },
            {
              "criteria": "cpe:2.3:a:indusoft:web_studio:6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82BF1958-F098-4E55-B97C-F15253A63228"
            },
            {
              "criteria": "cpe:2.3:a:indusoft:web_studio:6.1:sp6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88A43470-16F3-4B89-A8A3-8B77880A315D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "PSIRT-CNA@flexerasoftware.com"
}