CVE-2011-4039

EUVD-2011-3991
Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access violation."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
dreamreportdream_report
𝑥
≤ 3.43
dreamreportdream_report
3.21
dreamreportdream_report
3.41
dreamreportdream_report
3.42
invensyswonderware_hmi_reports
𝑥
≤ 3.42.835.0304
𝑥
= Vulnerable software versions
Common Weakness Enumeration