ID

VAR-201312-0503


TITLE

GE Proficy Machine Edition 'Trapiserver.exe' Remote Buffer Overflow Vulnerability

Trust: 1.1

sources: IVD: a209c786-1efa-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-14827 // BID: 63943

DESCRIPTION

GE Intelligent Platforms Proficy HMI/SCADA\342\200\223iFIX is the world's leading industrial automation software solution that provides process visualization, data acquisition and data monitoring for production operations. GE Proficy Machine Edition has an overflow vulnerability in the implementation of Trapi File Server (Trapiserver.exe), which is triggered by specially crafted HTTP messages. Causes a buffer overflow that causes a denial of service. Successfully exploiting this issue may allow an attacker to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will result in a denial-of-service condition. GE Proficy Machine Edition 7.00 SIM 7 is vulnerable

Trust: 0.99

sources: CNVD: CNVD-2013-14827 // BID: 63943 // IVD: a209c786-1efa-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: a209c786-1efa-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-14827

AFFECTED PRODUCTS

vendor:general electricmodel:proficy machine edition simscope:eqversion:7.007

Trust: 0.8

vendor:generalmodel:electric proficy machine edition simscope:eqversion:7.007

Trust: 0.3

vendor:generalmodel:electric proficy machine edition simscope:neversion:7.008

Trust: 0.3

sources: IVD: a209c786-1efa-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-14827 // BID: 63943

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-14827
value: HIGH

Trust: 0.6

IVD: a209c786-1efa-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

CNVD: CNVD-2013-14827
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: a209c786-1efa-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: a209c786-1efa-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-14827

THREAT TYPE

network

Trust: 0.3

sources: BID: 63943

TYPE

Failure to Handle Exceptional Conditions

Trust: 0.3

sources: BID: 63943

PATCH

title:GE Proficy Machine Edition 'Trapiserver.exe' patch for remote buffer overflow vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/41397

Trust: 0.6

sources: CNVD: CNVD-2013-14827

EXTERNAL IDS

db:BIDid:63943

Trust: 0.9

db:CNVDid:CNVD-2013-14827

Trust: 0.8

db:OSVDBid:100316

Trust: 0.6

db:IVDid:A209C786-1EFA-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: a209c786-1efa-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-14827 // BID: 63943

REFERENCES

url:http://osvdb.org/100316

Trust: 0.6

url:http://www.ge-ip.com/

Trust: 0.3

url:http://www.ge-ip.com/products/proficy-view-machine-edition/p2823

Trust: 0.3

url:http://support.ge-ip.com/support/resources/sites/ge_fanuc_support/content/live/kb/14000/kb14870/en_us/geip12-06%20security%20advisory%20-%20buffer%20overflow%20in%20proficy%20view.pdf

Trust: 0.3

sources: CNVD: CNVD-2013-14827 // BID: 63943

CREDITS

Unknown

Trust: 0.3

sources: BID: 63943

SOURCES

db:IVDid:a209c786-1efa-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2013-14827
db:BIDid:63943

LAST UPDATE DATE

2022-05-17T02:05:55.782000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-14827date:2013-12-03T00:00:00
db:BIDid:63943date:2012-04-24T00:00:00

SOURCES RELEASE DATE

db:IVDid:a209c786-1efa-11e6-abef-000c29c66e3ddate:2013-12-03T00:00:00
db:CNVDid:CNVD-2013-14827date:2013-12-03T00:00:00
db:BIDid:63943date:2012-04-24T00:00:00