Gravité: : Critique
  Identifiant(s) CVE: : CVE-2012-2516
  Date du conseil: 21 juillet 2015

  Description

An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows remote attackers to execute arbitrary commands via crafted input, related to a "command injection vulnerability."

  Information Exposure Rating:

Apply associated Trend Micro DPI Rules.

  Solutions

  Trend Micro Deep Security DPI Rule Number: 1005190
  Trend Micro Deep Security DPI Rule Name: 1005190 - Identified GE Proficy Historian KeyHelp ActiveX Control With LaunchTriPane Function

  Affected software and version:

  • ge intelligent_platforms_proficy_batch_execution 5.6
  • ge intelligent_platforms_proficy_historian 3.1
  • ge intelligent_platforms_proficy_historian 3.5
  • ge intelligent_platforms_proficy_historian 4.0
  • ge intelligent_platforms_proficy_historian 4.5
  • ge intelligent_platforms_proficy_hmi/scada_ifix 5.0
  • ge intelligent_platforms_proficy_hmi/scada_ifix 5.1
  • ge intelligent_platforms_proficy_pulse 1.0
  • ge intelligent_platforms_si7_i/o_driver 7.20
  • ge intelligent_platforms_si7_i/o_driver 7.42