ID

VAR-201207-0381


CVE

CVE-2012-1832


TITLE

WellinTech KingView Vulnerable to arbitrary code execution

Trust: 0.8

sources: JVNDB: JVNDB-2012-003010

DESCRIPTION

WellinTech KingView 6.53 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted packet to (1) TCP or (2) UDP port 2001. KingView is a product for building data information service platforms for industrial automation. A security vulnerability exists in WellinTech KingView that allows an attacker to send a specially crafted message to the TCP 2001 or UPD 2001 port, which can trigger the reading of illegal memory domain data, causing the application to crash. WellinTech KingView is prone to multiple memory corruption vulnerabilities and a directory-traversal vulnerability. An attacker can exploit these issues to access arbitrary files within the context of the affected application and execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition. WellinTech KingView 6.53 is vulnerable. ---------------------------------------------------------------------- Become a PSI 3.0 beta tester! Test-drive the new beta version and tell us what you think about its extended automatic update function and significantly enhanced user-interface. Download it here! http://secunia.com/psi_30_beta_launch ---------------------------------------------------------------------- TITLE: KingHistorian Memory Corruption Vulnerability SECUNIA ADVISORY ID: SA49765 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/49765/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=49765 RELEASE DATE: 2012-07-09 DISCUSS ADVISORY: http://secunia.com/advisories/49765/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/49765/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=49765 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: A vulnerability has been reported in KingHistorian, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an invalid pointer write error, which can be exploited to corrupt memory via a specially crafted packet sent to port 5678. Successful exploitation may allow execution of arbitrary code. The vulnerability is reported in version 3.0. SOLUTION: Install patch. Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ PROVIDED AND/OR DISCOVERED BY: ICS-CERT credits Dillon Beresford. ORIGINAL ADVISORY: ICS-CERT: http://www.us-cert.gov/control_systems/pdf/ICSA-12-185-01.pdf OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 2.7

sources: NVD: CVE-2012-1832 // JVNDB: JVNDB-2012-003010 // CNVD: CNVD-2012-3532 // BID: 54280 // IVD: b14cc34e-2353-11e6-abef-000c29c66e3d // PACKETSTORM: 114551

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: b14cc34e-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-3532

AFFECTED PRODUCTS

vendor:wellintechmodel:kingviewscope:eqversion:6.53

Trust: 2.3

vendor:wellintechmodel:kingviewscope:eqversion:65.30.17249

Trust: 1.6

vendor:wellintechmodel:kingviewscope:eqversion:65.30.2010.18018

Trust: 1.6

vendor:wellintechmodel:kingviewscope:eqversion:6.5.30.2010.18018

Trust: 1.6

vendor:wellintechmodel:kingviewscope:eqversion:3.0

Trust: 1.6

vendor:wellintechmodel:kingviewscope:eqversion:6.52

Trust: 1.6

vendor:wellintechmodel:kingviewscope:lteversion:6.53

Trust: 1.0

vendor:kingviewmodel: - scope:eqversion:3.0

Trust: 0.2

vendor:kingviewmodel: - scope:eqversion:6.5.30.2010.18018

Trust: 0.2

vendor:kingviewmodel: - scope:eqversion:6.52

Trust: 0.2

vendor:kingviewmodel: - scope:eqversion:*

Trust: 0.2

vendor:kingviewmodel: - scope:eqversion:65.30.2010.18018

Trust: 0.2

vendor:kingviewmodel: - scope:eqversion:65.30.17249

Trust: 0.2

sources: IVD: b14cc34e-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-3532 // BID: 54280 // JVNDB: JVNDB-2012-003010 // CNNVD: CNNVD-201207-046 // NVD: CVE-2012-1832

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-1832
value: HIGH

Trust: 1.0

NVD: CVE-2012-1832
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201207-046
value: CRITICAL

Trust: 0.6

IVD: b14cc34e-2353-11e6-abef-000c29c66e3d
value: CRITICAL

Trust: 0.2

nvd@nist.gov: CVE-2012-1832
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

IVD: b14cc34e-2353-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: b14cc34e-2353-11e6-abef-000c29c66e3d // JVNDB: JVNDB-2012-003010 // CNNVD: CNNVD-201207-046 // NVD: CVE-2012-1832

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.8

sources: JVNDB: JVNDB-2012-003010 // NVD: CVE-2012-1832

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201207-046

TYPE

Buffer overflow

Trust: 0.8

sources: IVD: b14cc34e-2353-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201207-046

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-003010

PATCH

title:Jun.27,2012 -Patch for KingView6.53url:http://www.wellintech.com/index.php/news/33-patch-for-kingview653

Trust: 0.8

title:Top Pageurl:http://www.wellintech.com/

Trust: 0.8

title:Top Pageurl:http://www.wellintech.co.jp/

Trust: 0.8

title:WellinTech KingView illegal read vulnerability patchurl:https://www.cnvd.org.cn/patchInfo/show/18572

Trust: 0.6

sources: CNVD: CNVD-2012-3532 // JVNDB: JVNDB-2012-003010

EXTERNAL IDS

db:NVDid:CVE-2012-1832

Trust: 3.5

db:ICS CERTid:ICSA-12-185-01

Trust: 3.1

db:CNVDid:CNVD-2012-3532

Trust: 0.8

db:CNNVDid:CNNVD-201207-046

Trust: 0.8

db:JVNDBid:JVNDB-2012-003010

Trust: 0.8

db:BIDid:54280

Trust: 0.3

db:IVDid:B14CC34E-2353-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:SECUNIAid:49765

Trust: 0.2

db:PACKETSTORMid:114551

Trust: 0.1

sources: IVD: b14cc34e-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-3532 // BID: 54280 // JVNDB: JVNDB-2012-003010 // PACKETSTORM: 114551 // CNNVD: CNNVD-201207-046 // NVD: CVE-2012-1832

REFERENCES

url:http://www.us-cert.gov/control_systems/pdf/icsa-12-185-01.pdf

Trust: 3.1

url:http://www.wellintech.com/index.php/news/33-patch-for-kingview653

Trust: 1.6

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-1832

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-1832

Trust: 0.8

url:http://www.kingview.com/

Trust: 0.3

url:http://secunia.com/psi_30_beta_launch

Trust: 0.1

url:http://secunia.com/advisories/49765/#comments

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/vulnerability_intelligence/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.1

url:http://secunia.com/advisories/49765/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=49765

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

sources: CNVD: CNVD-2012-3532 // BID: 54280 // JVNDB: JVNDB-2012-003010 // PACKETSTORM: 114551 // CNNVD: CNNVD-201207-046 // NVD: CVE-2012-1832

CREDITS

Carlos Mario Penagos Hollman and Dillon Beresford

Trust: 0.3

sources: BID: 54280

SOURCES

db:IVDid:b14cc34e-2353-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2012-3532
db:BIDid:54280
db:JVNDBid:JVNDB-2012-003010
db:PACKETSTORMid:114551
db:CNNVDid:CNNVD-201207-046
db:NVDid:CVE-2012-1832

LAST UPDATE DATE

2025-04-11T22:56:15.391000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2012-3532date:2015-11-24T00:00:00
db:BIDid:54280date:2015-03-19T09:08:00
db:JVNDBid:JVNDB-2012-003010date:2012-07-06T00:00:00
db:CNNVDid:CNNVD-201207-046date:2012-07-06T00:00:00
db:NVDid:CVE-2012-1832date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:IVDid:b14cc34e-2353-11e6-abef-000c29c66e3ddate:2012-07-09T00:00:00
db:CNVDid:CNVD-2012-3532date:2012-07-09T00:00:00
db:BIDid:54280date:2012-07-03T00:00:00
db:JVNDBid:JVNDB-2012-003010date:2012-07-06T00:00:00
db:PACKETSTORMid:114551date:2012-07-09T03:48:55
db:CNNVDid:CNNVD-201207-046date:2012-07-06T00:00:00
db:NVDid:CVE-2012-1832date:2012-07-05T03:23:18.323