ID

VAR-201202-0155


CVE

CVE-2011-4041


TITLE

Advantech/BroadWin WebAccess of webvrpcs.exe Vulnerable to arbitrary code execution

Trust: 0.8

sources: JVNDB: JVNDB-2012-001325

DESCRIPTION

webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592. Advantech/BroadWin SCADA WebAccess is a fully browser-based Human Machine Interface (HMI) and Monitoring and Data Acquisition (SCADA) house arrest. Advantech/BroadWin SCADA WebAccess is prone to multiple remote vulnerabilities including an information-disclosure issue and a remote code-execution issue. Other attacks may also be possible. Advantech/BroadWin SCADA WebAccess 7.0 is vulnerable; other versions may also be affected

Trust: 2.88

sources: NVD: CVE-2011-4041 // JVNDB: JVNDB-2012-001325 // CNVD: CNVD-2011-1203 // BID: 47008 // IVD: 27c87c84-2354-11e6-abef-000c29c66e3d // IVD: b1f17dd8-1f9a-11e6-abef-000c29c66e3d // VULMON: CVE-2011-4041

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 1.0

sources: IVD: 27c87c84-2354-11e6-abef-000c29c66e3d // IVD: b1f17dd8-1f9a-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1203

AFFECTED PRODUCTS

vendor:broadwinmodel:webaccessscope: - version: -

Trust: 1.4

vendor:broadwinmodel:webaccessscope:eqversion:*

Trust: 1.0

vendor:advantechmodel:advantech/broadwin scada webaccessscope:eqversion:7.0

Trust: 0.9

vendor:webaccessmodel: - scope:eqversion:*

Trust: 0.4

sources: IVD: 27c87c84-2354-11e6-abef-000c29c66e3d // IVD: b1f17dd8-1f9a-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1203 // BID: 47008 // JVNDB: JVNDB-2012-001325 // CNNVD: CNNVD-201202-105 // NVD: CVE-2011-4041

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2011-4041
value: HIGH

Trust: 1.0

NVD: CVE-2011-4041
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201202-105
value: CRITICAL

Trust: 0.6

IVD: 27c87c84-2354-11e6-abef-000c29c66e3d
value: CRITICAL

Trust: 0.2

IVD: b1f17dd8-1f9a-11e6-abef-000c29c66e3d
value: CRITICAL

Trust: 0.2

VULMON: CVE-2011-4041
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2011-4041
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

IVD: 27c87c84-2354-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

IVD: b1f17dd8-1f9a-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 27c87c84-2354-11e6-abef-000c29c66e3d // IVD: b1f17dd8-1f9a-11e6-abef-000c29c66e3d // VULMON: CVE-2011-4041 // JVNDB: JVNDB-2012-001325 // CNNVD: CNNVD-201202-105 // NVD: CVE-2011-4041

PROBLEMTYPE DATA

problemtype:CWE-94

Trust: 1.8

sources: JVNDB: JVNDB-2012-001325 // NVD: CVE-2011-4041

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201202-105

TYPE

Code injection

Trust: 1.0

sources: IVD: 27c87c84-2354-11e6-abef-000c29c66e3d // IVD: b1f17dd8-1f9a-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201202-105

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-001325

EXPLOIT AVAILABILITY

sources: VULMON: CVE-2011-4041

PATCH

title:Top Pageurl:http://www.broadwin.com/Products.htm

Trust: 0.8

title:Offices Distributorsurl:http://www.broadwin.com/Offices.htm

Trust: 0.8

sources: JVNDB: JVNDB-2012-001325

EXTERNAL IDS

db:NVDid:CVE-2011-4041

Trust: 3.2

db:BIDid:47008

Trust: 2.6

db:ICS CERTid:ICSA-11-094-02A

Trust: 2.0

db:ICS CERT ALERTid:ICS-ALERT-11-081-01

Trust: 1.1

db:CNNVDid:CNNVD-201202-105

Trust: 1.0

db:ICS CERTid:ICSA-11-094-02B

Trust: 0.9

db:CNVDid:CNVD-2011-1203

Trust: 0.8

db:JVNDBid:JVNDB-2012-001325

Trust: 0.8

db:BUGTRAQid:20110322 SCADA TROJANS: ATTACKING THE GRID + ADVANTECH VULNERABILITIES

Trust: 0.6

db:IVDid:27C87C84-2354-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:IVDid:B1F17DD8-1F9A-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:EXPLOIT-DBid:35495

Trust: 0.1

db:VULMONid:CVE-2011-4041

Trust: 0.1

sources: IVD: 27c87c84-2354-11e6-abef-000c29c66e3d // IVD: b1f17dd8-1f9a-11e6-abef-000c29c66e3d // CNVD: CNVD-2011-1203 // VULMON: CVE-2011-4041 // BID: 47008 // JVNDB: JVNDB-2012-001325 // CNNVD: CNNVD-201202-105 // NVD: CVE-2011-4041

REFERENCES

url:http://reversemode.com/index.php?option=com_content&task=view&id=72&itemid=1

Trust: 2.6

url:http://www.us-cert.gov/control_systems/pdf/icsa-11-094-02a.pdf

Trust: 2.0

url:http://www.securityfocus.com/bid/47008

Trust: 1.8

url:http://www.securityfocus.com/archive/1/517117

Trust: 1.7

url:http://www.reversemode.com/downloads/exploit_advantech.zip

Trust: 1.7

url:http://www.reversemode.com/downloads/scada_trojans_ruben_rootedcon.pdf

Trust: 1.7

url:http://www.us-cert.gov/control_systems/pdf/ics-alert-11-081-01.pdf

Trust: 1.1

url:http://ics-cert.us-cert.gov/advisories/icsa-11-094-02b

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2011-4041

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2011-4041

Trust: 0.8

url:http://webaccess.advantech.com/product.php

Trust: 0.3

url:/archive/1/517117

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/94.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://www.exploit-db.com/exploits/35495/

Trust: 0.1

sources: CNVD: CNVD-2011-1203 // VULMON: CVE-2011-4041 // BID: 47008 // JVNDB: JVNDB-2012-001325 // CNNVD: CNNVD-201202-105 // NVD: CVE-2011-4041

CREDITS

Ruben Santamarta

Trust: 0.3

sources: BID: 47008

SOURCES

db:IVDid:27c87c84-2354-11e6-abef-000c29c66e3d
db:IVDid:b1f17dd8-1f9a-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2011-1203
db:VULMONid:CVE-2011-4041
db:BIDid:47008
db:JVNDBid:JVNDB-2012-001325
db:CNNVDid:CNNVD-201202-105
db:NVDid:CVE-2011-4041

LAST UPDATE DATE

2025-04-11T23:08:52.012000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-1203date:2011-03-24T00:00:00
db:VULMONid:CVE-2011-4041date:2012-12-11T00:00:00
db:BIDid:47008date:2014-01-09T02:01:00
db:JVNDBid:JVNDB-2012-001325date:2012-02-08T00:00:00
db:CNNVDid:CNNVD-201202-105date:2012-02-07T00:00:00
db:NVDid:CVE-2011-4041date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:IVDid:27c87c84-2354-11e6-abef-000c29c66e3ddate:2012-02-07T00:00:00
db:IVDid:b1f17dd8-1f9a-11e6-abef-000c29c66e3ddate:2011-03-24T00:00:00
db:CNVDid:CNVD-2011-1203date:2011-03-24T00:00:00
db:VULMONid:CVE-2011-4041date:2012-02-06T00:00:00
db:BIDid:47008date:2011-03-23T00:00:00
db:JVNDBid:JVNDB-2012-001325date:2012-02-08T00:00:00
db:CNNVDid:CNNVD-201202-105date:2012-02-07T00:00:00
db:NVDid:CVE-2011-4041date:2012-02-06T20:55:02.267