Vulnerability Details CVE-2011-4039
Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access violation."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.034
EPSS Ranking 86.9%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2011-4039
-
cpe:2.3:a:dreamreport:dream_report:*
-
cpe:2.3:a:dreamreport:dream_report:3.21
-
cpe:2.3:a:dreamreport:dream_report:3.41
-
cpe:2.3:a:dreamreport:dream_report:3.42
-
cpe:2.3:a:invensys:wonderware_hmi_reports:*