ID

VAR-201902-0886


TITLE

Kingview 7.5sp2 Denial of service vulnerability

Trust: 0.8

sources: IVD: a307ed87-fc45-4067-a7c7-1f4c144eeb45 // CNVD: CNVD-2019-05344

DESCRIPTION

KingView is an industrial automation configuration software produced by Beijing Yakong Technology Development Co., Ltd. Kingview 7.5sp2 has a denial-of-service vulnerability. The vulnerability originates from the use of wcslen to determine the length of a string when the file is closed, but fails to verify whether the string is available. An attacker can use this vulnerability to cause a denial of service

Trust: 0.72

sources: CNVD: CNVD-2019-05344 // IVD: a307ed87-fc45-4067-a7c7-1f4c144eeb45

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: a307ed87-fc45-4067-a7c7-1f4c144eeb45 // CNVD: CNVD-2019-05344

AFFECTED PRODUCTS

vendor:yakongmodel:kingview 7.5sp2scope: - version: -

Trust: 0.6

vendor:yakongmodel:kingview( kingview 7.5sp2scope:eqversion:)

Trust: 0.2

sources: IVD: a307ed87-fc45-4067-a7c7-1f4c144eeb45 // CNVD: CNVD-2019-05344

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-05344
value: MEDIUM

Trust: 0.6

IVD: a307ed87-fc45-4067-a7c7-1f4c144eeb45
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2019-05344
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: a307ed87-fc45-4067-a7c7-1f4c144eeb45
severity: MEDIUM
baseScore: 4.9
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: a307ed87-fc45-4067-a7c7-1f4c144eeb45 // CNVD: CNVD-2019-05344

TYPE

Denial of service

Trust: 0.2

sources: IVD: a307ed87-fc45-4067-a7c7-1f4c144eeb45

PATCH

title:Kingview 7.5sp2 Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/150197

Trust: 0.6

sources: CNVD: CNVD-2019-05344

EXTERNAL IDS

db:CNVDid:CNVD-2019-05344

Trust: 0.8

db:IVDid:A307ED87-FC45-4067-A7C7-1F4C144EEB45

Trust: 0.2

sources: IVD: a307ed87-fc45-4067-a7c7-1f4c144eeb45 // CNVD: CNVD-2019-05344

SOURCES

db:IVDid:a307ed87-fc45-4067-a7c7-1f4c144eeb45
db:CNVDid:CNVD-2019-05344

LAST UPDATE DATE

2022-05-17T02:09:43.842000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-05344date:2019-02-27T00:00:00

SOURCES RELEASE DATE

db:IVDid:a307ed87-fc45-4067-a7c7-1f4c144eeb45date:2019-02-26T00:00:00
db:CNVDid:CNVD-2019-05344date:2019-03-01T00:00:00