Description
Buffer overflow in the WebClient ActiveX control in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to execute arbitrary code via a long string in a parameter associated with the location URL.
References (4)
Core 4
Core References
US Government Resource x_refsource_misc
http://www.us-cert.gov/control_systems/pdf/ICSA-11-343-01.pdf
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72117
Patch, Vendor Advisory x_refsource_confirm
http://www.usdata.com/sea/factorylink/en/p_nav5.asp
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/51266
Scores
EPSS
0.0549
EPSS Percentile
90.3%
Details
CWE
CWE-119
Status
published
Products (3)
siemens/tecnomatix_factorylink
6.6.1
siemens/tecnomatix_factorylink
7.5.217
siemens/tecnomatix_factorylink
8.0.2.54
Published
Jan 08, 2012
Tracked Since
Feb 18, 2026