CVE-2012-0257
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the Open member, leading to a function-pointer overwrite.
Published:Apr 2, 2012
Last Modified:Apr 11, 2025
EPS:Apr 2, 2012
EPSS Score:0.03138
CVSS Score:6.8
Affected Products
Vendor
Product
Action
Vendor
Invensys
Product
Archestra Application Object Toolkit
Invensys
Archestra Application Object Toolkit
Vendor
Invensys
Product
Foxboro Control Software
Invensys
Foxboro Control Software
Vendor
Invensys
Product
Infusion Control Edition
Invensys
Infusion Control Edition
Vendor
Invensys
Product
Infusion Foundation Edition
Invensys
Infusion Foundation Edition
Vendor
Invensys
Product
Infusion Scada
Invensys
Infusion Scada
Vendor
Invensys
Product
Intouch
Invensys
Intouch
Vendor
Invensys
Product
Wonderware Application Server
Invensys
Wonderware Application Server
Vendor
Invensys
Product
Wonderware Information Server
Invensys
Wonderware Information Server
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
