CVE-2011-3330

Schneider Electric Unity Pro <= 6.0 - Buffer Overflow in UnitelWay Windows Device Driver

Title source: llm
STIX 2.1

Description

Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers, to execute arbitrary code via an unspecified system parameter.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/70882
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50319
US Government Resource x_refsource_misc
http://www.us-cert.gov/control_systems/pdf/ICSA-11-277-01.pdf
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46534
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026234

Scores

EPSS 0.0146
EPSS Percentile 81.1%

Details

CWE
CWE-119
Status published
Products (6)
schneider-electric/monitor_pro < 7.6
schneider-electric/opc_factory_server < 3.34
schneider-electric/pl7_pro < 4.5
schneider-electric/telemecanique_driver_pack < 2.6
schneider-electric/unity_pro < 6.0
schneider-electric/vijeo_citect < 7.20
Published Nov 04, 2011
Tracked Since Feb 18, 2026