Invensys
Invensys Wonderware Information Server: vulnerabilidades y CVE
Invensys Wonderware Information Server tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2014-5399 | Alta (7.5) | 1.6% | — | 28 ago 2014 | SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |
| CVE-2014-5398 | Baja (2.1) | 0.56% | — | 28 ago 2014 | Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with… |
| CVE-2014-5397 | Media (4.3) | 1.5% | — | 28 ago 2014 | Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2014-2381 | Baja (2.1) | 0.14% | — | 28 ago 2014 | Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file. |
| CVE-2014-2380 | Alta (7.8) | 0.75% | — | 28 ago 2014 | Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file. |
| CVE-2013-0688 | Media (4.3) | 1.0% | — | 9 may 2013 | Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-0686 | Alta (9.3) | 2.1% | — | 9 may 2013 | Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory… |
| CVE-2013-0685 | Alta (9.3) | 3.3% | — | 9 may 2013 | Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values, which allows remote attackers to execute arbitrary code or cause a denial of… |
| CVE-2013-0684 | Alta (7.5) | 1.3% | — | 9 may 2013 | SQL injection vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |
| CVE-2012-3005 | Media (6.9) | 0.45% | — | 26 jul 2012 | Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and… |
| CVE-2012-0258 | Media (6.8) | 3.2% | — | 2 abr 2012 | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA… |
| CVE-2012-0257 | Media (6.8) | 3.2% | — | 2 abr 2012 | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA… |
| CVE-2012-0228 | Alta (7.5) | 2.2% | — | 2 abr 2012 | Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass intended access restrictions via unspecified vectors. |
| CVE-2012-0226 | Alta (7.5) | 1.7% | — | 2 abr 2012 | SQL injection vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |
| CVE-2012-0225 | Media (4.3) | 1.5% | — | 2 abr 2012 | Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2011-2962 | Alta (9.3) | 4.6% | — | 29 jul 2011 | Multiple stack-based buffer overflows in Invensys Wonderware Information Server 3.1, 4.0, and 4.0 SP1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via two unspecified… |
Otros productos de Invensys
Wonderware Application Server · 5Wonderware Inbatch · 4Intouch · 4Foxboro Control Software · 3Archestra Application Object Toolkit · 2Infusion Control Edition · 2Infusion Foundation Edition · 2Infusion Scada · 2Intouch/wonderware Application Server · 2Wonderware HMI Reports · 2Wonderware Intouch · 2Dasabcip · 1