This application requires Javascript for optimal performance.

General.Electric.ihDataArchiver.Service.Remote.Overflow

Release Date

Dec 24, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a Buffer Overflow vulnerability in
General Electric Proficy Historian.

The vulnerability is caused by an error when the vulnerable software handles
a malicious request. It allows a remote attacker to execute arbitrary code via sending a crafted request.

Affected Products

General Electric Proficy Historian version 4.0.0.176
General Electric Proficy Historian version 3.5.0.259
General Electric Proficy HMI SCADA - iFIX version 5.1

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-1918

Reference: VID-30445