CVE-2013-2827: Wellintech Kingalarm&event
High severity, CVSS 7.5. EPSS: 48.3% chance of exploitation in the next 30 days.
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers to download arbitrary DLL code onto a client machine and execute this code via the ProjectURL property value.
Affected products
- Wellintech Kingalarm&event: up to and including 2.0.2
- Wellintech Kinggraphic: up to and including 3.1
- Wellintech Kingscada: up to and including 3.1
Published 2014-01-15. Last modified 2026-06-16.