Monday, July 27, 2026

Looking Back – 3-8-2011 – KingView Exploit

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today, a blog post from March 8th, 2011, ICS-CERT Alert for WellinTech KingView, made the list. The ICS Alert briefly describes a vulnerability in the WellinTech KingView v6.53. Not much in the way of details about the vulnerability beyond the fact that it affected KVWebSvr.dll and an exploit was available. Interestingly, neither the alert nor the follow-up advisory provide a CVE for the vulnerability.  

It turns out that the supporting CVE (CVE-2011-3142) was not published until August 16th, 2011, and MITRE was the CNA not ICS-CERT (they became a CNA in 2012). Two separate exploits are listed in the NVD.NIST.gov record, but neither link works. In fact, none of the links referenced on the NVD site work. Ancient history, so I guess it really is not important.... 

No comments:

 
/* Use this with templates/template-twocol.html */