CVE-2011-4870
Last modified
CVE-2011-4870 is a vulnerability of currently unknown severity. Multiple buffer overflows in the (1) GUIControls, (2) BatchObjSrv, and (3) BatchSecCtrl ActiveX controls in Invensys Wonderware InBatch 9.0 and 9.0 SP1, and InBatch 8.1 SP1, 9.0 SP2, and 9.5 Server and Runtime Clients, allow remote attackers to execute arbitrary code via a long string in a property value, a different issue than CVE-2011-3141.. EPSS estimates a 2.49% chance of exploitation in the next 30 days.
Description
Multiple buffer overflows in the (1) GUIControls, (2) BatchObjSrv, and (3) BatchSecCtrl ActiveX controls in Invensys Wonderware InBatch 9.0 and 9.0 SP1, and InBatch 8.1 SP1, 9.0 SP2, and 9.5 Server and Runtime Clients, allow remote attackers to execute arbitrary code via a long string in a property value, a different issue than CVE-2011-3141.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Invensys | Wonderware Inbatch | 8.1 | Sp1 |
| Invensys | Wonderware Inbatch | 9.0 | — |
| Invensys | Wonderware Inbatch | 9.5 | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-4870?
How severe is CVE-2011-4870?
How do I fix CVE-2011-4870?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-4864The Tencent MobileQQ (com.tencent.mobileqq) application 2.2 …
- CVE-2011-4865The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad…
- CVE-2011-4866The Kaixin001 (com.kaixin001.activity) application 1.3.1 and…
- CVE-2011-4867The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 f…
- CVE-2011-4868The logging functionality in dhcpd in ISC DHCP before 4.2.3-…
- CVE-2011-4869validator/val_nsec3.c in Unbound before 1.4.13p2 does not pr…
- CVE-2011-4871Open Automation Software OPC Systems.NET before 5.0 allows r…
- CVE-2011-4872Multiple HTC Android devices including Desire HD FRG83D and …
- CVE-2011-4873Unspecified vulnerability in the server in Certec EDV atvise…
- CVE-2011-4874Use-after-free vulnerability in MICROSYS PROMOTIC before 8.1…
- CVE-2011-4875Stack-based buffer overflow in HmiLoad in the runtime loader…
- CVE-2011-4876Directory traversal vulnerability in HmiLoad in the runtime …
Are you affected by CVE-2011-4870?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
