9.3
CVE-2011-4875
- EPSS 41.01%
- Published 03.02.2012 20:55:01
- Last modified 11.04.2025 00:51:21
- Source cret@cert.org
- Teams watchlist Login
- Open Login
Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute arbitrary code via vectors related to Unicode strings.
Data is provided by the National Vulnerability Database (NVD)
Siemens ≫ Wincc Flexible Version2004
Siemens ≫ Wincc Flexible Version2005
Siemens ≫ Wincc Flexible Version2007
Siemens ≫ Wincc Flexible Version2008
Siemens ≫ Simatic Hmi Panels Versioncomfort_panels
Siemens ≫ Simatic Hmi Panels Versionmobile_panels
Siemens ≫ Simatic Hmi Panels Versionmp
Siemens ≫ Simatic Hmi Panels Versionop
Siemens ≫ Simatic Hmi Panels Versiontp
Siemens ≫ Wincc Runtime Advanced Versionv11
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 41.01% | 0.973 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.