invensys records
27 published records for vendor invensys.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 12
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-20 Improper Input Validation3
- CWE-326 Inadequate Encryption Strength2
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2010-4557Proof of concept | Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series Batch 8.1 and possiinvensys · wonderware inbatch · CWE-119 | Critical10.0 | — | 12.1% | Dec 17, 2010 |
38Monitor | CVE-2011-2962No exploit | Multiple stack-based buffer overflows in Invensys Wonderware Information Server 3.1, 4.0, and 4.0 SP1 allow remote attackers to cause a deniinvensys · wonderware information server · CWE-119 | Critical9.3 | — | 4.6% | Jul 29, 2011 |
38Monitor | CVE-2010-2974No exploit | Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX invensys · wonderware archestra configuration access component activex control · CWE-119 | Critical9.3 | — | 4.5% | Aug 5, 2010 |
38Monitor | CVE-2011-4039No exploit | Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows invensys · wonderware hmi reports · CWE-264 | Critical9.3 | — | 4.1% | Feb 10, 2012 |
38Monitor | CVE-2011-3141No exploit | Buffer overflow in the InBatch BatchField ActiveX control for Invensys Wonderware InBatch 8.1 SP1, 9.0, and 9.0 SP1 allows remote attackers invensys · wonderware inbatch · CWE-119 | Critical9.3 | — | 4.0% | Aug 16, 2011 |
38Monitor | CVE-2013-0685No exploit | Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values, invensys · wonderware information server · CWE-264 | Critical9.3 | — | 3.3% | May 9, 2013 |
38Monitor | CVE-2013-0686No exploit | Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to read arbitrary files, send invensys · wonderware information server · CWE-20 | Critical9.3 | — | 2.1% | May 9, 2013 |
38Monitor | CVE-2012-4710No exploit | Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, oinvensys · wonderware win-xml exporter · CWE-20 | Critical9.3 | — | 2.1% | Apr 4, 2013 |
31Monitor | CVE-2012-0228No exploit | Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass invensys · wonderware information server · CWE-264 | High7.5 | — | 2.2% | Apr 2, 2012 |
31Monitor | CVE-2012-0226No exploit | SQL injection vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to execute arbitrary SQL commainvensys · wonderware information server · CWE-89 | High7.5 | — | 1.7% | Apr 2, 2012 |
31Monitor | CVE-2014-2380No exploit | Schneider Electric Wonderware Inadequate Encryption Strengthinvensys · wonderware information server · CWE-326 | High7.8 | — | 0.8% | Aug 27, 2014 |
30Monitor | CVE-2014-5399No exploit | Schneider Electric Wonderware SQL Injectioninvensys · wonderware information server · CWE-89 | High7.5 | — | 1.6% | Aug 27, 2014 |
30Monitor | CVE-2013-0684No exploit | SQL injection vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackersinvensys · wonderware information server · CWE-89 | High7.5 | — | 1.3% | May 9, 2013 |
28Monitor | CVE-2012-0258No exploit | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 20invensys · archestra application object toolkit · CWE-119 | Medium6.8 | — | 3.2% | Apr 2, 2012 |
28Monitor | CVE-2012-0257No exploit | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 20invensys · archestra application object toolkit · CWE-119 | Medium6.8 | — | 3.2% | Apr 2, 2012 |
28Monitor | CVE-2011-4870No exploit | Multiple buffer overflows in the (1) GUIControls, (2) BatchObjSrv, and (3) BatchSecCtrl ActiveX controls in Invensys Wonderware InBatch 9.0 invensys · wonderware inbatch · CWE-119 | Medium6.8 | — | 2.4% | Jan 7, 2012 |
27Monitor | CVE-2012-4709No exploit | Invensys Wonderware InTouch HMI 2012 R2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers,invensys · wonderware intouch · CWE-119 | Medium6.9 | — | 0.6% | Oct 13, 2013 |
27Monitor | CVE-2012-3005No exploit | Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Ininvensys · foxboro control software | Medium6.9 | — | 0.4% | Jul 26, 2012 |
21Monitor | CVE-2012-3007No exploit | Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as usinvensys · dasabcip · CWE-119 | Medium5.0 | — | 2.2% | Jul 4, 2012 |
20Monitor | CVE-2012-3847No exploit | slssvc.exe in Invensys Wonderware SuiteLink in Invensys InTouch 2012 and Wonderware Application Server 2012 allows remote attackers to causeinvensys · intouch · CWE-399 | Medium5.0 | — | 1.3% | Jul 4, 2012 |
18Monitor | CVE-2011-4038No exploit | Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Rinvensys · wonderware hmi reports · CWE-79 | Medium4.3 | — | 2.1% | Feb 10, 2012 |
17Monitor | CVE-2014-5397No exploit | Schneider Electric Wonderware Cross-site Scriptinginvensys · wonderware information server · CWE-79 | Medium4.3 | — | 1.5% | Aug 27, 2014 |
17Monitor | CVE-2012-0225No exploit | Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to inject arbitrainvensys · wonderware information server · CWE-79 | Medium4.3 | — | 1.5% | Apr 2, 2012 |
17Monitor | CVE-2013-0688No exploit | Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows reminvensys · wonderware information server · CWE-79 | Medium4.3 | — | 1.0% | May 9, 2013 |
8Monitor | CVE-2014-5398No exploit | Schneider Electric Wonderware Input Validationinvensys · wonderware information server · CWE-20 | Low2.1 | — | 0.6% | Aug 27, 2014 |
- CVE-2010-455744Plan
Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series Batch 8.1 and possi
CriticalCVSS 10.0Proof of conceptEPSS 12%invensys · wonderware inbatchDec 17, 2010
- CVE-2011-296238Monitor
Multiple stack-based buffer overflows in Invensys Wonderware Information Server 3.1, 4.0, and 4.0 SP1 allow remote attackers to cause a deni
CriticalCVSS 9.3No exploitEPSS 5%invensys · wonderware information serverJul 29, 2011
- CVE-2010-297438Monitor
Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX
CriticalCVSS 9.3No exploitEPSS 4%invensys · wonderware archestra configuration access component activex controlAug 5, 2010
- CVE-2011-403938Monitor
Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows
CriticalCVSS 9.3No exploitEPSS 4%invensys · wonderware hmi reportsFeb 10, 2012
- CVE-2011-314138Monitor
Buffer overflow in the InBatch BatchField ActiveX control for Invensys Wonderware InBatch 8.1 SP1, 9.0, and 9.0 SP1 allows remote attackers
CriticalCVSS 9.3No exploitEPSS 4%invensys · wonderware inbatchAug 16, 2011
- CVE-2013-068538Monitor
Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values,
CriticalCVSS 9.3No exploitEPSS 3%invensys · wonderware information serverMay 9, 2013
- CVE-2013-068638Monitor
Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to read arbitrary files, send
CriticalCVSS 9.3No exploitEPSS 2%invensys · wonderware information serverMay 9, 2013
- CVE-2012-471038Monitor
Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, o
CriticalCVSS 9.3No exploitEPSS 2%invensys · wonderware win-xml exporterApr 4, 2013
- CVE-2012-022831Monitor
Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass
HighCVSS 7.5No exploitEPSS 2%invensys · wonderware information serverApr 2, 2012
- CVE-2012-022631Monitor
SQL injection vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to execute arbitrary SQL comma
HighCVSS 7.5No exploitEPSS 2%invensys · wonderware information serverApr 2, 2012
- CVE-2014-238031Monitor
Schneider Electric Wonderware Inadequate Encryption Strength
HighCVSS 7.8No exploitEPSS 1%invensys · wonderware information serverAug 27, 2014
- CVE-2014-539930Monitor
Schneider Electric Wonderware SQL Injection
HighCVSS 7.5No exploitEPSS 2%invensys · wonderware information serverAug 27, 2014
- CVE-2013-068430Monitor
SQL injection vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers
HighCVSS 7.5No exploitEPSS 1%invensys · wonderware information serverMay 9, 2013
- CVE-2012-025828Monitor
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 20
MediumCVSS 6.8No exploitEPSS 3%invensys · archestra application object toolkitApr 2, 2012
- CVE-2012-025728Monitor
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 20
MediumCVSS 6.8No exploitEPSS 3%invensys · archestra application object toolkitApr 2, 2012
- CVE-2011-487028Monitor
Multiple buffer overflows in the (1) GUIControls, (2) BatchObjSrv, and (3) BatchSecCtrl ActiveX controls in Invensys Wonderware InBatch 9.0
MediumCVSS 6.8No exploitEPSS 2%invensys · wonderware inbatchJan 7, 2012
- CVE-2012-470927Monitor
Invensys Wonderware InTouch HMI 2012 R2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers,
MediumCVSS 6.9No exploitEPSS 1%invensys · wonderware intouchOct 13, 2013
- CVE-2012-300527Monitor
Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware In
MediumCVSS 6.9No exploitEPSS 0%invensys · foxboro control softwareJul 26, 2012
- CVE-2012-300721Monitor
Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as us
MediumCVSS 5.0No exploitEPSS 2%invensys · dasabcipJul 4, 2012
- CVE-2012-384720Monitor
slssvc.exe in Invensys Wonderware SuiteLink in Invensys InTouch 2012 and Wonderware Application Server 2012 allows remote attackers to cause
MediumCVSS 5.0No exploitEPSS 1%invensys · intouchJul 4, 2012
- CVE-2011-403818Monitor
Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream R
MediumCVSS 4.3No exploitEPSS 2%invensys · wonderware hmi reportsFeb 10, 2012
- CVE-2014-539717Monitor
Schneider Electric Wonderware Cross-site Scripting
MediumCVSS 4.3No exploitEPSS 2%invensys · wonderware information serverAug 27, 2014
- CVE-2012-022517Monitor
Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to inject arbitra
MediumCVSS 4.3No exploitEPSS 2%invensys · wonderware information serverApr 2, 2012
- CVE-2013-068817Monitor
Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows rem
MediumCVSS 4.3No exploitEPSS 1%invensys · wonderware information serverMay 9, 2013
- CVE-2014-53988Monitor
Schneider Electric Wonderware Input Validation
LowCVSS 2.1No exploitEPSS 1%invensys · wonderware information serverAug 27, 2014