Severity: : Critical
  CVE Kennungen: : CVE-2012-2516
  Advisory Date: 21 de июля de 2015

  DESCRIPTION

An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows remote attackers to execute arbitrary commands via crafted input, related to a "command injection vulnerability."

  INFORMATION EXPOSURE

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1005190
  Trend Micro Deep Security DPI Rule Name: 1005190 - Identified GE Proficy Historian KeyHelp ActiveX Control With LaunchTriPane Function

  AFFECTED SOFTWARE AND VERSION:

  • ge intelligent_platforms_proficy_batch_execution 5.6
  • ge intelligent_platforms_proficy_historian 3.1
  • ge intelligent_platforms_proficy_historian 3.5
  • ge intelligent_platforms_proficy_historian 4.0
  • ge intelligent_platforms_proficy_historian 4.5
  • ge intelligent_platforms_proficy_hmi/scada_ifix 5.0
  • ge intelligent_platforms_proficy_hmi/scada_ifix 5.1
  • ge intelligent_platforms_proficy_pulse 1.0
  • ge intelligent_platforms_si7_i/o_driver 7.20
  • ge intelligent_platforms_si7_i/o_driver 7.42