Schneider-Electric Citectscada Reports vulnerabilities

4 known vulnerabilities affecting schneider-electric/citectscada_reports.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2011-4034CRITICALCVSS 9.3≤ 4.10v4.02011-12-02
CVE-2011-4034 [CRITICAL] CWE-119 CVE-2011-4034: Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historia Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.
nvd
CVE-2011-4036MEDIUMCVSS 5.0≤ 4.10v4.02011-12-02
CVE-2011-4036 [MEDIUM] CWE-22 CVE-2011-4036: Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHist Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
nvd
CVE-2011-4033MEDIUMCVSS 4.3≤ 4.10v4.02011-12-02
CVE-2011-4033 [MEDIUM] CWE-119 CVE-2011-4033: Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historia Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2011-4035MEDIUMCVSS 4.3≤ 4.10v4.02011-12-02
CVE-2011-4035 [MEDIUM] CWE-79 CVE-2011-4035: Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, Cit Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd