peter bassill · operator
$ cve CVE-2012-2516 JSON

CVE-2012-2516 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 39.7% (pctl 99)

Patch early

A public exploit exists.

Description

An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows remote attackers to execute arbitrary commands via crafted input, related to a "command injection vulnerability."

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS39.71% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2012-07-05
Last modified2026-06-16

Affected (5)

VendorProduct
geintelligent platforms proficy batch execution
geintelligent platforms proficy historian
geintelligent platforms proficy hmi\/scada ifix
geintelligent platforms proficy pulse
geintelligent platforms si7 i\/o driver

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD