Buffer overflow in the WebClient ActiveX control in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to execute arbitrary code via a long string in a parameter associated with the location URL.
References
Link | Resource |
---|---|
http://www.usdata.com/sea/factorylink/en/p_nav5.asp | Patch Vendor Advisory |
http://www.us-cert.gov/control_systems/pdf/ICSA-11-343-01.pdf | US Government Resource |
http://www.securityfocus.com/bid/51266 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/72117 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-01-07 16:55
Updated : 2017-08-28 18:30
NVD link : CVE-2011-4055
Mitre link : CVE-2011-4055
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
siemens
- tecnomatix_factorylink