Записи invensys
27 опубликованных записей вендора invensys.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 12
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-20 Improper Input Validation3
- CWE-326 Inadequate Encryption Strength2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
27 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2010-4557Proof of concept | Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series Batch 8.1 and possiinvensys · wonderware inbatch · CWE-119 | Критическая10,0 | — | 12,1 % | 17 дек. 2010 г. |
38Наблюдать | CVE-2011-2962Эксплойта нет | Multiple stack-based buffer overflows in Invensys Wonderware Information Server 3.1, 4.0, and 4.0 SP1 allow remote attackers to cause a deniinvensys · wonderware information server · CWE-119 | Критическая9,3 | — | 4,6 % | 29 июл. 2011 г. |
38Наблюдать | CVE-2010-2974Эксплойта нет | Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX invensys · wonderware archestra configuration access component activex control · CWE-119 | Критическая9,3 | — | 4,5 % | 5 авг. 2010 г. |
38Наблюдать | CVE-2011-4039Эксплойта нет | Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows invensys · wonderware hmi reports · CWE-264 | Критическая9,3 | — | 4,1 % | 10 февр. 2012 г. |
38Наблюдать | CVE-2011-3141Эксплойта нет | Buffer overflow in the InBatch BatchField ActiveX control for Invensys Wonderware InBatch 8.1 SP1, 9.0, and 9.0 SP1 allows remote attackers invensys · wonderware inbatch · CWE-119 | Критическая9,3 | — | 4,0 % | 16 авг. 2011 г. |
38Наблюдать | CVE-2013-0685Эксплойта нет | Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values, invensys · wonderware information server · CWE-264 | Критическая9,3 | — | 3,3 % | 9 мая 2013 г. |
38Наблюдать | CVE-2013-0686Эксплойта нет | Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to read arbitrary files, send invensys · wonderware information server · CWE-20 | Критическая9,3 | — | 2,1 % | 9 мая 2013 г. |
38Наблюдать | CVE-2012-4710Эксплойта нет | Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, oinvensys · wonderware win-xml exporter · CWE-20 | Критическая9,3 | — | 2,1 % | 4 апр. 2013 г. |
31Наблюдать | CVE-2012-0228Эксплойта нет | Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass invensys · wonderware information server · CWE-264 | Высокая7,5 | — | 2,2 % | 2 апр. 2012 г. |
31Наблюдать | CVE-2012-0226Эксплойта нет | SQL injection vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to execute arbitrary SQL commainvensys · wonderware information server · CWE-89 | Высокая7,5 | — | 1,7 % | 2 апр. 2012 г. |
31Наблюдать | CVE-2014-2380Эксплойта нет | Schneider Electric Wonderware Inadequate Encryption Strengthinvensys · wonderware information server · CWE-326 | Высокая7,8 | — | 0,8 % | 27 авг. 2014 г. |
30Наблюдать | CVE-2014-5399Эксплойта нет | Schneider Electric Wonderware SQL Injectioninvensys · wonderware information server · CWE-89 | Высокая7,5 | — | 1,6 % | 27 авг. 2014 г. |
30Наблюдать | CVE-2013-0684Эксплойта нет | SQL injection vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackersinvensys · wonderware information server · CWE-89 | Высокая7,5 | — | 1,3 % | 9 мая 2013 г. |
28Наблюдать | CVE-2012-0258Эксплойта нет | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 20invensys · archestra application object toolkit · CWE-119 | Средняя6,8 | — | 3,2 % | 2 апр. 2012 г. |
28Наблюдать | CVE-2012-0257Эксплойта нет | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 20invensys · archestra application object toolkit · CWE-119 | Средняя6,8 | — | 3,2 % | 2 апр. 2012 г. |
28Наблюдать | CVE-2011-4870Эксплойта нет | Multiple buffer overflows in the (1) GUIControls, (2) BatchObjSrv, and (3) BatchSecCtrl ActiveX controls in Invensys Wonderware InBatch 9.0 invensys · wonderware inbatch · CWE-119 | Средняя6,8 | — | 2,4 % | 7 янв. 2012 г. |
27Наблюдать | CVE-2012-4709Эксплойта нет | Invensys Wonderware InTouch HMI 2012 R2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers,invensys · wonderware intouch · CWE-119 | Средняя6,9 | — | 0,6 % | 13 окт. 2013 г. |
27Наблюдать | CVE-2012-3005Эксплойта нет | Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Ininvensys · foxboro control software | Средняя6,9 | — | 0,4 % | 26 июл. 2012 г. |
21Наблюдать | CVE-2012-3007Эксплойта нет | Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as usinvensys · dasabcip · CWE-119 | Средняя5,0 | — | 2,2 % | 4 июл. 2012 г. |
20Наблюдать | CVE-2012-3847Эксплойта нет | slssvc.exe in Invensys Wonderware SuiteLink in Invensys InTouch 2012 and Wonderware Application Server 2012 allows remote attackers to causeinvensys · intouch · CWE-399 | Средняя5,0 | — | 1,3 % | 4 июл. 2012 г. |
18Наблюдать | CVE-2011-4038Эксплойта нет | Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Rinvensys · wonderware hmi reports · CWE-79 | Средняя4,3 | — | 2,1 % | 10 февр. 2012 г. |
17Наблюдать | CVE-2014-5397Эксплойта нет | Schneider Electric Wonderware Cross-site Scriptinginvensys · wonderware information server · CWE-79 | Средняя4,3 | — | 1,5 % | 27 авг. 2014 г. |
17Наблюдать | CVE-2012-0225Эксплойта нет | Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to inject arbitrainvensys · wonderware information server · CWE-79 | Средняя4,3 | — | 1,5 % | 2 апр. 2012 г. |
17Наблюдать | CVE-2013-0688Эксплойта нет | Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows reminvensys · wonderware information server · CWE-79 | Средняя4,3 | — | 1,0 % | 9 мая 2013 г. |
8Наблюдать | CVE-2014-5398Эксплойта нет | Schneider Electric Wonderware Input Validationinvensys · wonderware information server · CWE-20 | Низкая2,1 | — | 0,6 % | 27 авг. 2014 г. |
- CVE-2010-455744В плане
Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series Batch 8.1 and possi
КритическаяCVSS 10,0Proof of conceptEPSS 12 %invensys · wonderware inbatch17 дек. 2010 г.
- CVE-2011-296238Наблюдать
Multiple stack-based buffer overflows in Invensys Wonderware Information Server 3.1, 4.0, and 4.0 SP1 allow remote attackers to cause a deni
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %invensys · wonderware information server29 июл. 2011 г.
- CVE-2010-297438Наблюдать
Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %invensys · wonderware archestra configuration access component activex control5 авг. 2010 г.
- CVE-2011-403938Наблюдать
Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %invensys · wonderware hmi reports10 февр. 2012 г.
- CVE-2011-314138Наблюдать
Buffer overflow in the InBatch BatchField ActiveX control for Invensys Wonderware InBatch 8.1 SP1, 9.0, and 9.0 SP1 allows remote attackers
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %invensys · wonderware inbatch16 авг. 2011 г.
- CVE-2013-068538Наблюдать
Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values,
КритическаяCVSS 9,3Эксплойта нетEPSS 3 %invensys · wonderware information server9 мая 2013 г.
- CVE-2013-068638Наблюдать
Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to read arbitrary files, send
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %invensys · wonderware information server9 мая 2013 г.
- CVE-2012-471038Наблюдать
Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, o
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %invensys · wonderware win-xml exporter4 апр. 2013 г.
- CVE-2012-022831Наблюдать
Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %invensys · wonderware information server2 апр. 2012 г.
- CVE-2012-022631Наблюдать
SQL injection vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to execute arbitrary SQL comma
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %invensys · wonderware information server2 апр. 2012 г.
- CVE-2014-238031Наблюдать
Schneider Electric Wonderware Inadequate Encryption Strength
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %invensys · wonderware information server27 авг. 2014 г.
- CVE-2014-539930Наблюдать
Schneider Electric Wonderware SQL Injection
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %invensys · wonderware information server27 авг. 2014 г.
- CVE-2013-068430Наблюдать
SQL injection vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %invensys · wonderware information server9 мая 2013 г.
- CVE-2012-025828Наблюдать
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 20
СредняяCVSS 6,8Эксплойта нетEPSS 3 %invensys · archestra application object toolkit2 апр. 2012 г.
- CVE-2012-025728Наблюдать
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 20
СредняяCVSS 6,8Эксплойта нетEPSS 3 %invensys · archestra application object toolkit2 апр. 2012 г.
- CVE-2011-487028Наблюдать
Multiple buffer overflows in the (1) GUIControls, (2) BatchObjSrv, and (3) BatchSecCtrl ActiveX controls in Invensys Wonderware InBatch 9.0
СредняяCVSS 6,8Эксплойта нетEPSS 2 %invensys · wonderware inbatch7 янв. 2012 г.
- CVE-2012-470927Наблюдать
Invensys Wonderware InTouch HMI 2012 R2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers,
СредняяCVSS 6,9Эксплойта нетEPSS 1 %invensys · wonderware intouch13 окт. 2013 г.
- CVE-2012-300527Наблюдать
Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware In
СредняяCVSS 6,9Эксплойта нетEPSS 0 %invensys · foxboro control software26 июл. 2012 г.
- CVE-2012-300721Наблюдать
Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as us
СредняяCVSS 5,0Эксплойта нетEPSS 2 %invensys · dasabcip4 июл. 2012 г.
- CVE-2012-384720Наблюдать
slssvc.exe in Invensys Wonderware SuiteLink in Invensys InTouch 2012 and Wonderware Application Server 2012 allows remote attackers to cause
СредняяCVSS 5,0Эксплойта нетEPSS 1 %invensys · intouch4 июл. 2012 г.
- CVE-2011-403818Наблюдать
Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream R
СредняяCVSS 4,3Эксплойта нетEPSS 2 %invensys · wonderware hmi reports10 февр. 2012 г.
- CVE-2014-539717Наблюдать
Schneider Electric Wonderware Cross-site Scripting
СредняяCVSS 4,3Эксплойта нетEPSS 2 %invensys · wonderware information server27 авг. 2014 г.
- CVE-2012-022517Наблюдать
Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to inject arbitra
СредняяCVSS 4,3Эксплойта нетEPSS 2 %invensys · wonderware information server2 апр. 2012 г.
- CVE-2013-068817Наблюдать
Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows rem
СредняяCVSS 4,3Эксплойта нетEPSS 1 %invensys · wonderware information server9 мая 2013 г.
- CVE-2014-53988Наблюдать
Schneider Electric Wonderware Input Validation
НизкаяCVSS 2,1Эксплойта нетEPSS 1 %invensys · wonderware information server27 авг. 2014 г.