CVE-2011-4034
published 2011-12-02CVE-2011-4034: Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and…
PriorityP355critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
13.94%
96.1th percentile
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | citecthistorian | <= 4.30 | — |
| schneider-electric | citecthistorian | — | — |
| schneider-electric | citectscada_reports | <= 4.10 | — |
| schneider-electric | citectscada_reports | — | — |
| schneider-electric | vijeo_historian | <= 4.30 | — |
| schneider-electric | vijeo_historian | — | — |
| schneider-electric | vijeo_historian | — | — |
| schneider-electric | vijeo_historian | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect instantiation of any of the five vulnerable TeeChart ActiveX CLSIDs in browser or document context; presence of these CLSIDs in registry or memory indicates a vulnerable/exploited control. ↗
- →Monitor for calls to the AddSeries() method on TeeChart ActiveX objects with overly large or negative integer arguments, which triggers the integer overflow leading to arbitrary code execution. ↗
- →The exploit is delivered via browser (drive-by) and targets IE8 with Java support for DEP bypass; monitor for TeeChart OCX files loaded within iexplore.exe process. ↗
- ·The exploit vector requires social engineering to deliver the malicious content to the victim; purely network-based exploitation without user interaction is not applicable for the TeeChart buffer overflow (CVE-2011-4034). ↗
- ·Multiple TeeChart OCX versions spanning back to 2001 are affected, so detection rules should cover all five listed CLSIDs/filenames rather than targeting only the latest version. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fqp8-j3rg-x5gf: Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4
ghsa_unreviewed·2022-05-17
CVE-2011-4034 [HIGH] CWE-119 GHSA-fqp8-j3rg-x5gf: Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.
CISA ICS
Schneider Electric Vijeo Historian Web Server Multiple Vulnerabilities
cisa_ics·2013-05-07
Schneider Electric Vijeo Historian Web Server Multiple Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Vijeo Historian Web Server Multiple Vulnerabilities
Last RevisedMay 07, 2013
Alert CodeICSA-11-307-01
## Overview
ICS-CERT originally released Advisory ICSA-11-307-01P on the US-CERT secure Portal on November 03, 2011. This web page release was delayed to allow users time to download and install the update.
Researcher Kuang-Chun Hung of Security Research and Service Institute--Information and Communication Security Technology Center (ICST) has identified four vulnerabilities in the Schneider Electric Vijeo Historian product line. These vulnerabilities include
No detection rules found.
No writeups or analysis indexed.
http://www.citect.com/index.php?option=com_content&view=article&id=1656&Itemid=1695http://www.scada.schneider-electric.com/sites/scada/en/login/historian-vulnerability.pagehttp://www.us-cert.gov/control_systems/pdf/ICSA-11-307-01.pdfhttp://www.citect.com/index.php?option=com_content&view=article&id=1656&Itemid=1695http://www.scada.schneider-electric.com/sites/scada/en/login/historian-vulnerability.pagehttp://www.us-cert.gov/control_systems/pdf/ICSA-11-307-01.pdf
2011-12-02
Published