Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

APP:INDUSOFT-WEBSTUDIO-RCE

Severity

Major

Recommended

No

Recommended Action

Drop

Category

APP

Keywords

InduSoft WebStudio Unauthenticated Remote Operations Remote Code Execution

Release Date

2015/06/12

Update Number

2504

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

APP: InduSoft WebStudio Unauthenticated Remote Operations Remote Code Execution


A code execution vulnerability has been identified in the Remote Agent component of InduSoft Web Studio. A successful attack can lead to arbitrary code execution.

Extended Description

CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and process control.

Affected Products

  • Indusoft web_studio 6.1
  • Indusoft web_studio 7.0

References

  • BugTraq: 50675
  • CVE: CVE-2011-4051

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out