CVE Database
/

CVE-2007-1313

Back to search

CVE-2007-1313

Published: Mar 21, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

NETxAutomation NETxEIB OPC Server before 3.0.1300 does not properly validate OLE for Process Control (OPC) server handles, which allows attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors involving the (1) IOPCSyncIO::Read, (2) IOPCSyncIO::Write, (3) IOPCServer::AddGroup, (4) IOPCServer::RemoveGroup, (5) IOPCCommon::SetClientName, and (6) IOPCGroupStateMgt::CloneGroup functions, which allow access to arbitrary memory. NOTE: the vectors might be limited to attackers with physical access.

VendorProductVersions

n/a

n/a

affected
n/a

References

1017803
vdb-entry
x_refsource_SECTRACK
VU#296593
third-party-advisory
x_refsource_CERT-VN
34440
vdb-entry
x_refsource_OSVDB
24612
third-party-advisory
x_refsource_SECUNIA
23059
vdb-entry
x_refsource_BID
ADV-2007-1038
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now