CVE-2011-4034
Status: ModifiedHigh (9.3)—
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Base score: 9.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 13%
- Percentile among all scored CVEs: 96
- Score date: 10/3/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (3)
CWEs
- CWE-119
References
- http://www.citect.com/index.php?option=com_content&view=article&id=1656&Itemid=1695
- http://www.scada.schneider-electric.com/sites/scada/en/login/historian-vulnerability.page
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-307-01.pdf
- http://www.citect.com/index.php?option=com_content&view=article&id=1656&Itemid=1695
- http://www.scada.schneider-electric.com/sites/scada/en/login/historian-vulnerability.page
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-307-01.pdf
Raw JSON (NVD)
Show
{
"id": "CVE-2011-4034",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-12-02T11:55:05.277",
"references": [
{
"url": "http://www.citect.com/index.php?option=com_content&view=article&id=1656&Itemid=1695",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://www.scada.schneider-electric.com/sites/scada/en/login/historian-vulnerability.page",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://www.us-cert.gov/control_systems/pdf/ICSA-11-307-01.pdf",
"tags": [
"Patch",
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.citect.com/index.php?option=com_content&view=article&id=1656&Itemid=1695",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.scada.schneider-electric.com/sites/scada/en/login/historian-vulnerability.page",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.us-cert.gov/control_systems/pdf/ICSA-11-307-01.pdf",
"tags": [
"Patch",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors."
},
{
"lang": "es",
"value": "Desbordamiento de búfer en el control ActiveX TeeChart Steema, tal como se utiliza en Schneider Electric Vijeo Historian v4.30 y anteriores, CitectHistorian v4.30 y anteriores, y CitectSCADAReports v4.10 y anteriores, permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio a través de vectores no especificados."
}
],
"lastModified": "2026-06-16T23:34:19.287",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:schneider-electric:vijeo_historian:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA173AD2-52AF-4401-9A29-757B68168B4D",
"versionEndIncluding": "4.30"
},
{
"criteria": "cpe:2.3:a:schneider-electric:vijeo_historian:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00E3E11B-E433-4D89-9525-8159CEC30DC0"
},
{
"criteria": "cpe:2.3:a:schneider-electric:vijeo_historian:4.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2788D1E5-206A-4AC8-AA28-65E5EE268B59"
},
{
"criteria": "cpe:2.3:a:schneider-electric:vijeo_historian:4.20:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "99B88BED-7F2F-4F89-9BD1-B7EDC1608531"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:schneider-electric:citecthistorian:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "859A64AD-1FB2-4A7C-AE4D-26951FC050F9",
"versionEndIncluding": "4.30"
},
{
"criteria": "cpe:2.3:a:schneider-electric:citecthistorian:4.20:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B491E331-B533-4E09-966E-45A3BE724C5A"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:schneider-electric:citectscada_reports:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "106C6198-C341-4B10-8788-A8FA51F137F1",
"versionEndIncluding": "4.10"
},
{
"criteria": "cpe:2.3:a:schneider-electric:citectscada_reports:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38765B0B-9C09-4BC0-9E50-D0C6E8969A77"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}