Check Point Reference: | CPAI-2013-3520 |
Date Published: | 12 Nov 2013 |
Severity: | Critical |
Last Updated: | Saturday 04 January, 2025 |
Source: | CVE-2011-4042 CVE-2011-4043 CVE-2011-4042 CVE-2011-4045 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | ARC Informatique PlantVue ARC Informatique PCVue 6 ARC Informatique PCVue 10.0 ARC Informatique FrontVue |
Vulnerability Description | A buffer overflow vulnerability has been reported in SCADA ARC PcVue. |
Vulnerability Details | The vulnerability is due to a boundary check error. A remote attacker can exploit this issue by enticing a victim to open a specially crafted HTML file with the affected product. Successful exploitation could allow an attacker to execute arbitrary commands on the system. |
This protection will detect and block the transferring of a specially crafted HTML file to the target.
In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.
SmartView Tracker will log the following entries:
Attack Name: SCADA Protection Violation
Attack Information: ARC PcVue ActiveX Control SCADA Remote Code Execution