Dream Report
Vendor:
First CVE: Feb 10, 2012 · Active for 14 years
5
Total CVEs
More Total CVEs than 79% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dream Report over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 10, 2012
14 years ago
Most Recent CVE
Apr 9, 2021
1,936 days ago
CVE Severity & Scoring
Dream Report5 CVEs
20%
80%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (60.0%)
Network0 (0.0%)
Unknown2 (40.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (60.0%)
High0 (0.0%)
Unknown2 (40.0%)
User Interaction
None1 (20.0%)
Unknown2 (40.0%)
Required2 (40.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None2 (40.0%)
Unknown2 (40.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4039HIGH Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execut | Feb 10, 2012 | 9.3 | 28 | NO | NO |
CVE-2020-13534HIGH A privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID), installed by Dream Report 5 20-2, reference LocalServer32 and InprocServer32 wit | Apr 9, 2021 | 7.8 | 20 | NO | NO |
CVE-2020-13533HIGH A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which reference binaries with weak permissions, can | Apr 9, 2021 | 7.8 | 20 | NO | NO |
CVE-2020-13532HIGH A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashboard Service service binary can be replaced by attackers to e | Apr 9, 2021 | 7.8 | 20 | NO | NO |
CVE-2011-4038MEDIUM Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, all | Feb 10, 2012 | 4.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Dream Report
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5_r20-2 | 3 | 7.8 | 0.6% | 0 | 0 |
| 3.42 | 2 | 6.8 | 2.8% | 0 | 0 |
| 3.41 | 2 | 6.8 | 2.8% | 0 | 0 |
| 3.21 | 2 | 6.8 | 2.8% | 0 | 0 |