9.3
CVSSv2

CVE-2012-2516

Published: 05/07/2012 Updated: 17/07/2012
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 up to and including 7.42; and other products, allows remote malicious users to execute arbitrary commands via crafted input, related to a "command injection vulnerability."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ge intelligent platforms proficy historian 3.1

ge intelligent platforms proficy historian 3.5

ge intelligent platforms proficy historian 4.5

ge intelligent platforms proficy hmi\\/scada ifix 5.1

ge intelligent platforms proficy batch execution 5.6

ge intelligent platforms si7 i\\/o driver 7.20

ge intelligent platforms si7 i\\/o driver 7.42

ge intelligent platforms proficy pulse 1.0

ge intelligent platforms proficy historian 4.0

ge intelligent platforms proficy hmi\\/scada ifix 5.0

Exploits

## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # web site for more information on licensing and terms of use # metasploitcom/ ## require 'msf/core' class Metasploit3 < Msf::Exploit::Remote Rank = ExcellentRanking include Msf::Exploit ...
This Metasploit module exploits a code execution vulnerability in the KeyScript ActiveX control from keyhelpocx It is packaged in several products or GE, such as Proficy Historian 45, 40, 35, and 31, Proficy HMI/SCADA 51 and 50, Proficy Pulse 10, Proficy Batch Execution 56, and SI7 I/O Driver between 720 and 742 When the control is ins ...