VDB
CVE-2007-4827
CVE-2007-4827
PUBLISHED
CVSS 7.5 HIGH
Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502.
EPSS 16.16% · 94.9th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
16.16%
94.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| automated_solutions | modbus_slave_activex_control | 0 |
Timeline
- Sep 19, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- modbus-tcpslave-bo(36677) vdb
- 1018707 vdb
- 20070918 TPTI-07-15: Automated Solutions Modbus TCP Slave ActiveX Control Heap Corruption Vulnerability mailing-list
- 38259 vdb
- http://dvlabs.tippingpoint.com/advisory/TPTI-07-15 url
- 25713 vdb
- http://www.nessus.org/plugins/index.php?view=single&id=26066 url
- VU#981849 third-party-advisory
- http://www.automatedsolutions.com/pub/asmbslv/ReadMe.htm url
- https://nvd.nist.gov/vuln/detail/CVE-2007-4827 advisory