GE Proficy Historian KeyHelp ActiveX LaunchTriPane Remote Code Execution Vulnerability
Data de publicação: 21 julho 2015
Schweregrad: : Crítico
Identificador(es) CVE: : CVE-2012-2516
Data do informe: 21 julho 2015
Descrição
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows remote attackers to execute arbitrary commands via crafted input, related to a "command injection vulnerability."
Exposição das informações
Apply associated Trend Micro DPI Rules.
Solução
Trend Micro Deep Security DPI Rule Number: 1005190
Trend Micro Deep Security DPI Rule Name: 1005190 - Identified GE Proficy Historian KeyHelp ActiveX Control With LaunchTriPane Function
Software infectado e versão:
- ge intelligent_platforms_proficy_batch_execution 5.6
- ge intelligent_platforms_proficy_historian 3.1
- ge intelligent_platforms_proficy_historian 3.5
- ge intelligent_platforms_proficy_historian 4.0
- ge intelligent_platforms_proficy_historian 4.5
- ge intelligent_platforms_proficy_hmi/scada_ifix 5.0
- ge intelligent_platforms_proficy_hmi/scada_ifix 5.1
- ge intelligent_platforms_proficy_pulse 1.0
- ge intelligent_platforms_si7_i/o_driver 7.20
- ge intelligent_platforms_si7_i/o_driver 7.42