ID

VAR-201110-0491


TITLE

IRAI AUTOMGEN Use After Free Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2011-4374

DESCRIPTION

IRAI AUTOMGEN is an industrial control simulation software. IRAI AUTOMGEN is vulnerable to loopholes due to the insufficiency of handling certain files. An attacker can use this problem to execute arbitrary code on an affected machine to achieve the purpose of the attack. A remote attacker successfully exploited this vulnerability to execute arbitrary code, which could cause a denial of service if the exploit failed

Trust: 0.72

sources: CNVD: CNVD-2011-4374 // IVD: 88bd28fc-1f83-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 88bd28fc-1f83-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-4374

AFFECTED PRODUCTS

vendor:iraimodel:automgenscope:lteversion:<=8.0.0.7

Trust: 0.8

sources: IVD: 88bd28fc-1f83-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-4374

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 88bd28fc-1f83-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

IVD: 88bd28fc-1f83-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 88bd28fc-1f83-11e6-abef-000c29c66e3d

TYPE

Access control error

Trust: 0.2

sources: IVD: 88bd28fc-1f83-11e6-abef-000c29c66e3d

EXTERNAL IDS

db:CNVDid:CNVD-2011-4374

Trust: 0.8

db:EXPLOITDBid:EDB-ID:17964

Trust: 0.6

db:EXPLOIT-DBid:17964

Trust: 0.6

db:IVDid:88BD28FC-1F83-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 88bd28fc-1f83-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-4374

REFERENCES

url:http://www.exploit-db.com/exploits/17964/

Trust: 0.6

sources: CNVD: CNVD-2011-4374

SOURCES

db:IVDid:88bd28fc-1f83-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2011-4374

LAST UPDATE DATE

2022-05-17T01:46:44.056000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-4374date:2011-10-20T00:00:00

SOURCES RELEASE DATE

db:IVDid:88bd28fc-1f83-11e6-abef-000c29c66e3ddate:2011-10-20T00:00:00
db:CNVDid:CNVD-2011-4374date:2011-10-20T00:00:00