VulnerabilityModified
CVE-2011-4056
An unspecified ActiveX control in ActBar.ocx in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to create or overwrite arbitrary files via the save method.
MEDIUM 5.8EPSS 1.02%
Does this matter?
Lower severity and a low EPSS score (1.02%). Track it; it rarely justifies an emergency change on its own.
Description
An unspecified ActiveX control in ActBar.ocx in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to create or overwrite arbitrary files via the save method.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 1.02% probability · 61th percentile
- CISA KEV
- Not listed
- Affected
- siemens/tecnomatix factorylink
- Source
- cret@cert.org
References
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-343-01.pdfUS Government Resource
- http://www.usdata.com/sea/factorylink/en/p_nav5.aspPatch, Vendor Advisory
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-343-01.pdfUS Government Resource
- http://www.usdata.com/sea/factorylink/en/p_nav5.aspPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.