Release date:
Updated on:
Affected Systems:
Siemens Tecnomatix FactoryLink 8.0.2.54
Siemens Tecnomatix FactoryLink 7.5.217
Siemens Tecnomatix FactoryLink 6.6.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51267
Cve id: CVE-2011-4056
Siemens FactoryLink can supervise, manage, and control industrial processes.
Siemens FactoryLink has a data corruption vulnerability in ActiveX component implementation. Remote attackers can input arbitrary data to save files to any location on the target system, as a result, arbitrary files on the target computer are overwritten.
<* Source: Kuang-Chun Hung
Link: http://www.us-cert.gov/control_systems/pdf/ICSA-11-343-01.pdf
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Siemens
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.plm.automation.siemens.com/en_us/products/tecnomatix/production_management/factorylink/index.shtml