CVE-2011-4039: Dreamreport Dream Report

High severity, CVSS 9.3. EPSS: 4.1% chance of exploitation in the next 30 days.

Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access violation."

Affected products

  • Dreamreport Dream Report: up to and including 3.43; version 3.21 only; version 3.41 only; version 3.42 only
  • Invensys Wonderware HMI Reports: up to and including 3.42.835.0304

Published 2012-02-10. Last modified 2026-06-16.