ID

VAR-201801-1718


TITLE

Zijinqiao monitoring configuration software has out-of-bounds memory vulnerability

Trust: 0.6

sources: CNVD: CNVD-2018-01005

DESCRIPTION

Zijinqiao monitoring configuration software is a general industrial configuration software developed by Zijinqiao Company in long-term scientific research and engineering practice. There is a memory out-of-bounds reading vulnerability in the Zijinqiao monitoring configuration software when opening a specific project. An attacker can use this vulnerability to cause information leakage or denial of service

Trust: 0.72

sources: CNVD: CNVD-2018-01005 // IVD: e2e1a3e0-39ab-11e9-8141-000c29342cb1

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: e2e1a3e0-39ab-11e9-8141-000c29342cb1 // CNVD: CNVD-2018-01005

AFFECTED PRODUCTS

vendor:zijinqiaomodel:monitoring configuration software realinfoscope:eqversion:v6.5

Trust: 0.8

sources: IVD: e2e1a3e0-39ab-11e9-8141-000c29342cb1 // CNVD: CNVD-2018-01005

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2018-01005
value: LOW

Trust: 0.6

IVD: e2e1a3e0-39ab-11e9-8141-000c29342cb1
value: LOW

Trust: 0.2

CNVD: CNVD-2018-01005
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: e2e1a3e0-39ab-11e9-8141-000c29342cb1
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: e2e1a3e0-39ab-11e9-8141-000c29342cb1 // CNVD: CNVD-2018-01005

TYPE

Permission permission and access control

Trust: 0.2

sources: IVD: e2e1a3e0-39ab-11e9-8141-000c29342cb1

PATCH

title:Zijinqiao configuration software has a memory read out-of-bounds vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/112671

Trust: 0.6

sources: CNVD: CNVD-2018-01005

EXTERNAL IDS

db:CNVDid:CNVD-2018-01005

Trust: 0.8

db:IVDid:E2E1A3E0-39AB-11E9-8141-000C29342CB1

Trust: 0.2

sources: IVD: e2e1a3e0-39ab-11e9-8141-000c29342cb1 // CNVD: CNVD-2018-01005

SOURCES

db:IVDid:e2e1a3e0-39ab-11e9-8141-000c29342cb1
db:CNVDid:CNVD-2018-01005

LAST UPDATE DATE

2022-05-17T02:10:30.628000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-01005date:2018-01-16T00:00:00

SOURCES RELEASE DATE

db:IVDid:e2e1a3e0-39ab-11e9-8141-000c29342cb1date:2018-01-16T00:00:00
db:CNVDid:CNVD-2018-01005date:2018-02-18T00:00:00