ID

VAR-201207-0380


CVE

CVE-2012-1831


TITLE

WellinTech KingView Heap Buffer Overflow Vulnerability

Trust: 0.8

sources: IVD: b1534016-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-3531

DESCRIPTION

Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555. KingView is a product for building data information service platforms for industrial automation. WellinTech KingView is prone to multiple memory corruption vulnerabilities and a directory-traversal vulnerability. Failed exploit attempts will result in a denial-of-service condition. WellinTech KingView 6.53 is vulnerable. ---------------------------------------------------------------------- Become a PSI 3.0 beta tester! Test-drive the new beta version and tell us what you think about its extended automatic update function and significantly enhanced user-interface. Download it here! http://secunia.com/psi_30_beta_launch ---------------------------------------------------------------------- TITLE: KingHistorian Memory Corruption Vulnerability SECUNIA ADVISORY ID: SA49765 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/49765/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=49765 RELEASE DATE: 2012-07-09 DISCUSS ADVISORY: http://secunia.com/advisories/49765/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/49765/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=49765 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: A vulnerability has been reported in KingHistorian, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an invalid pointer write error, which can be exploited to corrupt memory via a specially crafted packet sent to port 5678. Successful exploitation may allow execution of arbitrary code. The vulnerability is reported in version 3.0. SOLUTION: Install patch. Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ PROVIDED AND/OR DISCOVERED BY: ICS-CERT credits Dillon Beresford. ORIGINAL ADVISORY: ICS-CERT: http://www.us-cert.gov/control_systems/pdf/ICSA-12-185-01.pdf OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 2.7

sources: NVD: CVE-2012-1831 // JVNDB: JVNDB-2012-003009 // CNVD: CNVD-2012-3531 // BID: 54280 // IVD: b1534016-2353-11e6-abef-000c29c66e3d // PACKETSTORM: 114551

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: b1534016-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-3531

AFFECTED PRODUCTS

vendor:wellintechmodel:kingviewscope:eqversion:6.53

Trust: 2.3

vendor:wellintechmodel:kingviewscope:eqversion:65.30.17249

Trust: 1.6

vendor:wellintechmodel:kingviewscope:eqversion:65.30.2010.18018

Trust: 1.6

vendor:wellintechmodel:kingviewscope:eqversion:6.5.30.2010.18018

Trust: 1.6

vendor:wellintechmodel:kingviewscope:eqversion:3.0

Trust: 1.6

vendor:wellintechmodel:kingviewscope:eqversion:6.52

Trust: 1.6

vendor:wellintechmodel:kingviewscope:lteversion:6.53

Trust: 1.0

vendor:kingviewmodel: - scope:eqversion:3.0

Trust: 0.2

vendor:kingviewmodel: - scope:eqversion:6.5.30.2010.18018

Trust: 0.2

vendor:kingviewmodel: - scope:eqversion:6.52

Trust: 0.2

vendor:kingviewmodel: - scope:eqversion:*

Trust: 0.2

vendor:kingviewmodel: - scope:eqversion:65.30.2010.18018

Trust: 0.2

vendor:kingviewmodel: - scope:eqversion:65.30.17249

Trust: 0.2

sources: IVD: b1534016-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-3531 // BID: 54280 // JVNDB: JVNDB-2012-003009 // CNNVD: CNNVD-201207-045 // NVD: CVE-2012-1831

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-1831
value: HIGH

Trust: 1.0

NVD: CVE-2012-1831
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201207-045
value: CRITICAL

Trust: 0.6

IVD: b1534016-2353-11e6-abef-000c29c66e3d
value: CRITICAL

Trust: 0.2

nvd@nist.gov: CVE-2012-1831
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

IVD: b1534016-2353-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: b1534016-2353-11e6-abef-000c29c66e3d // JVNDB: JVNDB-2012-003009 // CNNVD: CNNVD-201207-045 // NVD: CVE-2012-1831

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.8

sources: JVNDB: JVNDB-2012-003009 // NVD: CVE-2012-1831

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201207-045

TYPE

Buffer overflow

Trust: 0.8

sources: IVD: b1534016-2353-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201207-045

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-003009

PATCH

title:Jun.27,2012 -Patch for KingView6.53url:http://www.wellintech.com/index.php/news/33-patch-for-kingview653

Trust: 0.8

title:Top Pageurl:http://www.wellintech.com/

Trust: 0.8

title:Top Pageurl:http://www.wellintech.co.jp/

Trust: 0.8

title:Patch for WellinTech KingView heap buffer overflow vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/18573

Trust: 0.6

sources: CNVD: CNVD-2012-3531 // JVNDB: JVNDB-2012-003009

EXTERNAL IDS

db:NVDid:CVE-2012-1831

Trust: 3.5

db:ICS CERTid:ICSA-12-185-01

Trust: 3.1

db:CNVDid:CNVD-2012-3531

Trust: 0.8

db:CNNVDid:CNNVD-201207-045

Trust: 0.8

db:JVNDBid:JVNDB-2012-003009

Trust: 0.8

db:BIDid:54280

Trust: 0.3

db:IVDid:B1534016-2353-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:SECUNIAid:49765

Trust: 0.2

db:PACKETSTORMid:114551

Trust: 0.1

sources: IVD: b1534016-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-3531 // BID: 54280 // JVNDB: JVNDB-2012-003009 // PACKETSTORM: 114551 // CNNVD: CNNVD-201207-045 // NVD: CVE-2012-1831

REFERENCES

url:http://www.us-cert.gov/control_systems/pdf/icsa-12-185-01.pdf

Trust: 3.1

url:http://www.wellintech.com/index.php/news/33-patch-for-kingview653

Trust: 1.6

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-1831

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-1831

Trust: 0.8

url:http://www.kingview.com/

Trust: 0.3

url:http://secunia.com/psi_30_beta_launch

Trust: 0.1

url:http://secunia.com/advisories/49765/#comments

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/vulnerability_intelligence/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.1

url:http://secunia.com/advisories/49765/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=49765

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

sources: CNVD: CNVD-2012-3531 // BID: 54280 // JVNDB: JVNDB-2012-003009 // PACKETSTORM: 114551 // CNNVD: CNNVD-201207-045 // NVD: CVE-2012-1831

CREDITS

Carlos Mario Penagos Hollman and Dillon Beresford

Trust: 0.3

sources: BID: 54280

SOURCES

db:IVDid:b1534016-2353-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2012-3531
db:BIDid:54280
db:JVNDBid:JVNDB-2012-003009
db:PACKETSTORMid:114551
db:CNNVDid:CNNVD-201207-045
db:NVDid:CVE-2012-1831

LAST UPDATE DATE

2025-04-11T22:56:15.311000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2012-3531date:2015-11-24T00:00:00
db:BIDid:54280date:2015-03-19T09:08:00
db:JVNDBid:JVNDB-2012-003009date:2012-07-06T00:00:00
db:CNNVDid:CNNVD-201207-045date:2012-07-06T00:00:00
db:NVDid:CVE-2012-1831date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:IVDid:b1534016-2353-11e6-abef-000c29c66e3ddate:2012-07-09T00:00:00
db:CNVDid:CNVD-2012-3531date:2012-07-09T00:00:00
db:BIDid:54280date:2012-07-03T00:00:00
db:JVNDBid:JVNDB-2012-003009date:2012-07-06T00:00:00
db:PACKETSTORMid:114551date:2012-07-09T03:48:55
db:CNNVDid:CNNVD-201207-045date:2012-07-06T00:00:00
db:NVDid:CVE-2012-1831date:2012-07-05T03:23:18.277