Input validation error in BizViz and GENESIS32 - CVE-2011-5088

 

Input validation error in BizViz and GENESIS32 - CVE-2011-5088

Published: April 18, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU44132
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2011-5088
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: ICONICS, Inc.
Affected software:
BizViz
GENESIS32

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The GENESIS32 IcoSetServer ActiveX control in ICONICS GENESIS32 9.21 and BizViz 9.21 configures the trusted zone on the basis of user input, which allows remote attackers to execute arbitrary code via a crafted web site, related to a "Workbench32/WebHMI component SetTrustedZone Policy vulnerability."


How to mitigate CVE-2011-5088

Install update from vendor's website.

Sources