CVE-2013-0108 describes a critical remote code execution vulnerability affecting Honeywell Enterprise Buildings Integrator (EBI), SymmetrE, and ComfortPoint Open Manager (CPO-M) Station products. This flaw resides in an ActiveX control within HscRemoteDeploy.dll, allowing attackers to execute arbitrary code via a crafted HTML document. With a CVSS score of 6.8, this vulnerability is easily exploitable over the network with medium attack complexity, potentially leading to full compromise of affected systems. While not listed on the KEV catalog, a Metasploit module and an ExploitDB entry confirm the existence of public exploit code, indicating a high potential for exploitation. Despite this, there is no evidence of active exploitation, social media discussion, or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
r310CPE matchmatch criteria | cpe:2.3:a:honeywell:enterprise_buildings_integrator:r310:*:*:*:*:*:*:* | ||
r400.2CPE matchmatch criteria | cpe:2.3:a:honeywell:enterprise_buildings_integrator:r400.2:*:*:*:*:*:*:* | ||
r410.1CPE matchmatch criteria | cpe:2.3:a:honeywell:enterprise_buildings_integrator:r410.1:*:*:*:*:*:*:* | ||
r410.2CPE matchmatch criteria | cpe:2.3:a:honeywell:enterprise_buildings_integrator:r410.2:*:*:*:*:*:*:* | ||
r310CPE matchmatch criteria | cpe:2.3:a:honeywell:symmetre:r310:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.