ID

VAR-201403-0551


CVE

CVE-2014-1614


TITLE

CenturyStar ActiveX (CamW2000.dll) SetMyAddress Function Special Parameters Handling Buffer Buffer Overflow Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2014-01831

DESCRIPTION

CenturyStar is a popular SCADA industrial control software. The SetMyAddress function in the CenturyStar CamW2000.dll ActiveX control has an overflow vulnerability when dealing with specially crafted parameters, allowing remote attackers to exploit exploits to build malicious web pages, tricking users into parsing, crashing an application, or executing arbitrary code. ** ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided

Trust: 0.72

sources: CNVD: CNVD-2014-01831 // IVD: d4ffcc7e-1ee3-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: d4ffcc7e-1ee3-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-01831

AFFECTED PRODUCTS

vendor:jichang qiu shi science andmodel:centurystarscope:eqversion:7.12

Trust: 0.8

sources: IVD: d4ffcc7e-1ee3-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-01831

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2014-01831
value: HIGH

Trust: 0.6

IVD: d4ffcc7e-1ee3-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

CNVD: CNVD-2014-01831
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: d4ffcc7e-1ee3-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: d4ffcc7e-1ee3-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-01831

TYPE

Buffer overflow

Trust: 0.2

sources: IVD: d4ffcc7e-1ee3-11e6-abef-000c29c66e3d

EXTERNAL IDS

db:NVDid:CVE-2014-1614

Trust: 0.8

db:CNVDid:CNVD-2014-01831

Trust: 0.8

db:OSVDBid:103359

Trust: 0.6

db:IVDid:D4FFCC7E-1EE3-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: d4ffcc7e-1ee3-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-01831

REFERENCES

url:http://osvdb.com/show/osvdb/103359

Trust: 0.6

sources: CNVD: CNVD-2014-01831

SOURCES

db:IVDid:d4ffcc7e-1ee3-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2014-01831

LAST UPDATE DATE

2022-05-04T08:57:35.886000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-01831date:2014-03-21T00:00:00

SOURCES RELEASE DATE

db:IVDid:d4ffcc7e-1ee3-11e6-abef-000c29c66e3ddate:2014-03-21T00:00:00
db:CNVDid:CNVD-2014-01831date:2014-03-19T00:00:00