|
|
|
|
| |
Credit:
The information has been provided by Kuang-Chun Hung .
The original article can be found at: http://www.securityfocus.com/bid/53753
|
| |
Vulnerable Systems:
* Emerson Electric Co DeltaV Workstations 9
* Emerson Electric Co DeltaV Workstations 11
* Emerson Electric Co DeltaV Workstations 10
* Emerson Electric Co DeltaV ProEssentials Scientific Graph 5
* Emerson Electric Co DeltaV 9
* Emerson Electric Co DeltaV 11
* Emerson Electric Co DeltaV 10
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, to access or modify data, to exploit latent vulnerabilities in the underlying database, to execute arbitrary code, to overwrite arbitrary files on the victim's computer in the context of the vulnerable application that is using the ActiveX control (typically Internet Explorer),or to cause a denial-of-service condition. Other attacks are possible.
Vendor Status:
Vendor had issued an update for this vulnerability
CVE Information:
CVE-2012-1814
Patch Availability:
http://www2.emersonprocess.com/en-US/brands/DeltaV/Pages/index.aspx
Disclosure Timeline:
Initial Release: May 16 2012
|
|
|
|
|