ID

VAR-201103-0378


TITLE

There are multiple security vulnerabilities in Iconics GENESIS32 and GENESIS64

Trust: 0.6

sources: CNVD: CNVD-2011-1178

DESCRIPTION

The Symantec LiveUpdate Administrator is a Symantec product upgrade management program. GENESIS32/64 is a new generation of industrial control software developed by ICONICS of the United States. GENESIS32/64 can trigger multiple memory corruption and integer overflow vulnerabilities due to incorrect validation of user-supplied input. Successful exploitation of a vulnerability can execute arbitrary code in an application security context. Failed exploit attempts will likely result in denial-of-service conditions. The following versions are vulnerable; other versions may also be affected: GENESIS32 9.21 GENESIS64 10.51

Trust: 0.99

sources: CNVD: CNVD-2011-1178 // BID: 46939 // IVD: 2335b7ac-1f9b-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 2335b7ac-1f9b-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1178

AFFECTED PRODUCTS

vendor:iconicsmodel:genesis32scope:eqversion:9.21

Trust: 1.1

vendor:iconicsmodel:genesis64scope:eqversion:10.51

Trust: 0.9

vendor:iconicsmodel:genesis32scope:eqversion:9.21.201.01

Trust: 0.3

vendor:iconicsmodel:genesis64scope:eqversion:10.51*

Trust: 0.2

sources: IVD: 2335b7ac-1f9b-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1178 // BID: 46939

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 2335b7ac-1f9b-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

IVD: 2335b7ac-1f9b-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.0
vectorString: AV:N/AC:M/AU:S/C:P/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.8
impactScore: 7.8
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0 [IVD]

Trust: 0.2

sources: IVD: 2335b7ac-1f9b-11e6-abef-000c29c66e3d

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201503-530

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201503-530

EXTERNAL IDS

db:BIDid:46939

Trust: 1.5

db:CNVDid:CNVD-2011-1178

Trust: 0.8

db:CNNVDid:CNNVD-201503-530

Trust: 0.6

db:IVDid:2335B7AC-1F9B-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 2335b7ac-1f9b-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1178 // BID: 46939 // CNNVD: CNNVD-201503-530

REFERENCES

url:http://www.securityfocus.com/bid/46939http

Trust: 0.6

url:http://www.securityfocus.com/bid/46939

Trust: 0.6

url:http://aluigi.org/adv/genesis_1-adv.txt

Trust: 0.3

url:http://aluigi.org/adv/genesis_10-adv.txt

Trust: 0.3

url:http://aluigi.org/adv/genesis_11-adv.txt

Trust: 0.3

url:http://aluigi.org/adv/genesis_12-adv.txt

Trust: 0.3

url:http://aluigi.org/adv/genesis_13-adv.txt

Trust: 0.3

url:http://aluigi.org/adv/genesis_2-adv.txt

Trust: 0.3

url:http://aluigi.org/adv/genesis_3-adv.txt

Trust: 0.3

url:http://aluigi.org/adv/genesis_4-adv.txt

Trust: 0.3

url:http://aluigi.org/adv/genesis_5-adv.txt

Trust: 0.3

url:http://aluigi.org/adv/genesis_6-adv.txt

Trust: 0.3

url:http://aluigi.org/adv/genesis_7-adv.txt

Trust: 0.3

url:http://aluigi.org/adv/genesis_8-adv.txt

Trust: 0.3

url:http://aluigi.org/adv/genesis_9-adv.txt

Trust: 0.3

url:http://www.iconics.com/home/products/hmi-and-scada/genesis32.aspx

Trust: 0.3

url:http://www.iconics.com/home/products/hmi-and-scada/genesis64.aspx

Trust: 0.3

url:/archive/1/517080

Trust: 0.3

sources: CNVD: CNVD-2011-1178 // BID: 46939 // CNNVD: CNNVD-201503-530

CREDITS

Luigi Auriemma

Trust: 0.9

sources: BID: 46939 // CNNVD: CNNVD-201503-530

SOURCES

db:IVDid:2335b7ac-1f9b-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2011-1178
db:BIDid:46939
db:CNNVDid:CNNVD-201503-530

LAST UPDATE DATE

2022-05-17T01:46:45.580000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-1178date:2011-03-22T00:00:00
db:BIDid:46939date:2015-03-19T09:13:00
db:CNNVDid:CNNVD-201503-530date:2015-03-25T00:00:00

SOURCES RELEASE DATE

db:IVDid:2335b7ac-1f9b-11e6-abef-000c29c66e3ddate:2011-03-22T00:00:00
db:CNVDid:CNVD-2011-1178date:2011-03-22T00:00:00
db:BIDid:46939date:2011-03-21T00:00:00
db:CNNVDid:CNNVD-201503-530date:2011-03-21T00:00:00