CVE-2011-10034 affects AUTOMGEN versions up to and including 8.0.0.7 (8.022), stemming from a use-after-free vulnerability in project file handling. This flaw allows an attacker to trigger a denial-of-service by presenting a malformed file, and in some scenarios, remote code execution may be possible. With a CVSS score of 6.9 (Medium) and an EPSS score of 0.0067, the vulnerability requires user interaction (UI:A) but can be exploited over a network (AV:N). There is no evidence of active exploitation, nor are there publicly available exploits in Metasploit or ExploitDB, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| IRAI | AUTOMGEN | >= 0, <= 8.0.0.7CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.