ID

VAR-201207-0058


CVE

CVE-2012-2559


TITLE

WellinTech KingHistorian Memory corruption vulnerability

Trust: 1.7

sources: IVD: b194c284-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-3527 // BID: 54282 // CNNVD: CNNVD-201207-047

DESCRIPTION

WellinTech KingHistorian 3.0 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer write) via a crafted packet to TCP port 5678. WellinTech KingHistorian is a data storage platform. WellinTech KingHistorian is prone to a memory corruption vulnerability. Failed exploit attempts will result in a denial-of-service condition. WellinTech KingHistorian 3.0 is vulnerable. ---------------------------------------------------------------------- Become a PSI 3.0 beta tester! Test-drive the new beta version and tell us what you think about its extended automatic update function and significantly enhanced user-interface. Download it here! http://secunia.com/psi_30_beta_launch ---------------------------------------------------------------------- TITLE: KingHistorian Memory Corruption Vulnerability SECUNIA ADVISORY ID: SA49765 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/49765/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=49765 RELEASE DATE: 2012-07-09 DISCUSS ADVISORY: http://secunia.com/advisories/49765/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/49765/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=49765 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: A vulnerability has been reported in KingHistorian, which can be exploited by malicious people to compromise a vulnerable system. Successful exploitation may allow execution of arbitrary code. The vulnerability is reported in version 3.0. SOLUTION: Install patch. Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ PROVIDED AND/OR DISCOVERED BY: ICS-CERT credits Dillon Beresford. ORIGINAL ADVISORY: ICS-CERT: http://www.us-cert.gov/control_systems/pdf/ICSA-12-185-01.pdf OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 2.7

sources: NVD: CVE-2012-2559 // JVNDB: JVNDB-2012-003011 // CNVD: CNVD-2012-3527 // BID: 54282 // IVD: b194c284-2353-11e6-abef-000c29c66e3d // PACKETSTORM: 114551

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: b194c284-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-3527

AFFECTED PRODUCTS

vendor:wellintechmodel:kinghistorianscope:eqversion:3.0

Trust: 3.3

vendor:kinghistorianmodel: - scope:eqversion:3.0

Trust: 0.2

sources: IVD: b194c284-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-3527 // BID: 54282 // JVNDB: JVNDB-2012-003011 // CNNVD: CNNVD-201207-047 // NVD: CVE-2012-2559

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-2559
value: HIGH

Trust: 1.0

NVD: CVE-2012-2559
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201207-047
value: CRITICAL

Trust: 0.6

IVD: b194c284-2353-11e6-abef-000c29c66e3d
value: CRITICAL

Trust: 0.2

nvd@nist.gov: CVE-2012-2559
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

IVD: b194c284-2353-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: b194c284-2353-11e6-abef-000c29c66e3d // JVNDB: JVNDB-2012-003011 // CNNVD: CNNVD-201207-047 // NVD: CVE-2012-2559

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.8

sources: JVNDB: JVNDB-2012-003011 // NVD: CVE-2012-2559

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201207-047

TYPE

Resource management error

Trust: 0.8

sources: IVD: b194c284-2353-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201207-047

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-003011

PATCH

title:Top Pageurl:http://en.wellintech.com/

Trust: 0.8

title:Top Pageurl:http://www.wellintech.co.jp/

Trust: 0.8

title:WellinTech KingHistorian Memory Corruption Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/18575

Trust: 0.6

sources: CNVD: CNVD-2012-3527 // JVNDB: JVNDB-2012-003011

EXTERNAL IDS

db:NVDid:CVE-2012-2559

Trust: 3.5

db:ICS CERTid:ICSA-12-185-01

Trust: 3.1

db:CNVDid:CNVD-2012-3527

Trust: 0.8

db:CNNVDid:CNNVD-201207-047

Trust: 0.8

db:JVNDBid:JVNDB-2012-003011

Trust: 0.8

db:BIDid:54282

Trust: 0.3

db:IVDid:B194C284-2353-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:SECUNIAid:49765

Trust: 0.2

db:PACKETSTORMid:114551

Trust: 0.1

sources: IVD: b194c284-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-3527 // BID: 54282 // JVNDB: JVNDB-2012-003011 // PACKETSTORM: 114551 // CNNVD: CNNVD-201207-047 // NVD: CVE-2012-2559

REFERENCES

url:http://www.us-cert.gov/control_systems/pdf/icsa-12-185-01.pdf

Trust: 3.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-2559

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-2559

Trust: 0.8

url:http://www.wellintech.com/

Trust: 0.3

url:http://en2.wellintech.com/products/detail.aspx?contentid=25

Trust: 0.3

url:http://secunia.com/psi_30_beta_launch

Trust: 0.1

url:http://secunia.com/advisories/49765/#comments

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/vulnerability_intelligence/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.1

url:http://secunia.com/advisories/49765/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=49765

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

sources: CNVD: CNVD-2012-3527 // BID: 54282 // JVNDB: JVNDB-2012-003011 // PACKETSTORM: 114551 // CNNVD: CNNVD-201207-047 // NVD: CVE-2012-2559

CREDITS

Carlos Mario Penagos Hollman and Dillon Beresford

Trust: 0.3

sources: BID: 54282

SOURCES

db:IVDid:b194c284-2353-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2012-3527
db:BIDid:54282
db:JVNDBid:JVNDB-2012-003011
db:PACKETSTORMid:114551
db:CNNVDid:CNNVD-201207-047
db:NVDid:CVE-2012-2559

LAST UPDATE DATE

2024-11-23T21:55:58.700000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2012-3527date:2012-07-09T00:00:00
db:BIDid:54282date:2012-07-03T00:00:00
db:JVNDBid:JVNDB-2012-003011date:2012-07-06T00:00:00
db:CNNVDid:CNNVD-201207-047date:2012-07-06T00:00:00
db:NVDid:CVE-2012-2559date:2024-11-21T01:39:13.630

SOURCES RELEASE DATE

db:IVDid:b194c284-2353-11e6-abef-000c29c66e3ddate:2012-07-09T00:00:00
db:CNVDid:CNVD-2012-3527date:2012-07-09T00:00:00
db:BIDid:54282date:2012-07-03T00:00:00
db:JVNDBid:JVNDB-2012-003011date:2012-07-06T00:00:00
db:PACKETSTORMid:114551date:2012-07-09T03:48:55
db:CNNVDid:CNNVD-201207-047date:2012-07-06T00:00:00
db:NVDid:CVE-2012-2559date:2012-07-05T03:23:18.573