CVE-2007-2938

CRITICAL ⚠ Exploit

Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is used, allows remote attackers to execute arbitrar...

Affects 2 products across 2 vendors.

BCS9.46
CVSS 2.010.0
EPSS40.5%
Percentile99th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

A critical buffer overflow vulnerability exists in the BaseRunner ActiveX control of the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) version 5.4.0.6, which can be exploited by remote attackers to execute arbitrary code. This affects systems using Internet Explorer 6 and poses significant risks to operational technology environments.

BSID: BS-2007-GLOBAL-172565-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2007-2938?
A critical buffer overflow vulnerability exists in the BaseRunner ActiveX control of the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) version 5.4.0.6, which can be exploited by remote attackers to execute arbitrary code. This affects systems using Internet Explorer 6 and poses significant risks to operational technology environments.
What is the CVSS score for CVE-2007-2938?
CVE-2007-2938 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 40.5%.
Is CVE-2007-2938 actively exploited?
Public exploit available for CVE-2007-2938. Exploitation risk elevated.
How do I remediate CVE-2007-2938?
Priority: IMMEDIATE. Advisory: http://secunia.com/advisories/25430 PSIRT: [email protected]
What systems are affected by CVE-2007-2938?
CVE-2007-2938 affects: Honeywell, Microsoft.
What NERC-CIP standard applies to CVE-2007-2938?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it allows unauthorized access to electronic security perimeters, which can lead to the compromise of critical control systems.
What IEC 62443 requirement maps to CVE-2007-2938?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a buffer overflow that can be exploited to execute arbitrary code, which is a common attack vector that must be mitigated to ensure the security of industrial control systems.
Vulnerability Details
CVE IDCVE-2007-2938
BSIDBS-2007-GLOBAL-172565-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2007-05-31
Last Modified2026-04-23
ICS Relevance55%
Verticals
ICS-OT
SourceNVD
Official Description

Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is used, allows remote attackers to execute arbitrary code via a long argument to the (1) Send485CMD method, and possibly the (2) SetLoginID, (3) AddSite, (4) SetScreen, and (5) SetVideoServer methods.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be triggered by sending a long argument to the Send485CMD method, and potentially other methods such as SetLoginID, AddSite, SetScreen, and SetVideoServer. The attack can be performed remotely without authentication, leading to complete compromise of the affected system.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Honeywell Ademco Atnbaseloader100 Module
Microsoft Internet Explorer
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 7005 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict input validation and length checks on all inputs to the affected methods. Consider deploying a web application firewall (WAF) to monitor and block suspicious requests.

SURICATA RULE
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"CVE-2007-2938 Ademco ATNBaseLoader100 Buffer Overflow Attempt"; flow:to_server,established; content:"Send485CMD"; fast_pattern; content:"|00|"; offset:0; depth:100; sid:9100002; rev:1;)
NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it allows unauthorized access to electronic security perimeters, which can lead to the compromise of critical control systems.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a buffer overflow that can be exploited to execute arbitrary code, which is a common attack vector that must be mitigated to ensure the security of industrial control systems.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash302935c33ebeede40c1561bb0aba38481690cb0d9b35fffaec0f27d29b059f5464c8a47c36d1016e82c24540710dfe633a8a0caaad95db18b71f83932b20f297
Related CVEs affecting Honeywell
CVE-2026-3611 10.0 The Honeywell IQ4x building management controller, exposes its full web-based... CVE-2022-31481 10.0 An unauthenticated attacker can send a specially crafted update file to the d... CVE-2021-38397 10.0 Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable ... CVE-2015-0984 10.0 Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL... CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2...
View all Honeywell CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →