HTTP: Invensys Wonderware Info Remote Code Execution

This signature detects attempts to use unsafe ActiveX controls in Invensys Wonderware. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

Invensys Wonderware Info Server is prone to a multiple unspecified remote code-esecution vulnerabilities in an unspecified ActiveX control. Attackers can exploit this issue to execute arbitrary code within the context of an application (typically Internet Explorer) that uses the ActiveX control. Failed exploit attempts will result in a denial-of-service condition. Invensys Wonderware Info Server versions 3.1, 4.0, and 4.0 SP1 are vulnerable.

Affected Products

Invensys wonderware_information_server

Short Name
HTTP:STC:ACTIVEX:WONDERWARE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2011-2962 Code Execution Info Invensys Remote Wonderware bid:48976
Release Date
08/18/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Invensys

CVSS Score

9.3

Found a potential security threat?