CVE-2011-4039

Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access violation."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
dreamreportdream_report
𝑥
≤ 3.43
dreamreportdream_report
3.21
dreamreportdream_report
3.41
dreamreportdream_report
3.42
invensyswonderware_hmi_reports
𝑥
≤ 3.42.835.0304
𝑥
= Vulnerable software versions
Common Weakness Enumeration