Skip to content
Noroxi

invensys records

27 published records for vendor invensys.

All records

27 records
  • Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series Batch 8.1 and possi

    CriticalCVSS 10.0Proof of conceptEPSS 12%

    invensys · wonderware inbatchDec 17, 2010

  • CVE-2011-2962
    38Monitor

    Multiple stack-based buffer overflows in Invensys Wonderware Information Server 3.1, 4.0, and 4.0 SP1 allow remote attackers to cause a deni

    CriticalCVSS 9.3No exploitEPSS 5%

    invensys · wonderware information serverJul 29, 2011

  • CVE-2010-2974
    38Monitor

    Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX

    CriticalCVSS 9.3No exploitEPSS 4%

    invensys · wonderware archestra configuration access component activex controlAug 5, 2010

  • CVE-2011-4039
    38Monitor

    Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows

    CriticalCVSS 9.3No exploitEPSS 4%

    invensys · wonderware hmi reportsFeb 10, 2012

  • CVE-2011-3141
    38Monitor

    Buffer overflow in the InBatch BatchField ActiveX control for Invensys Wonderware InBatch 8.1 SP1, 9.0, and 9.0 SP1 allows remote attackers

    CriticalCVSS 9.3No exploitEPSS 4%

    invensys · wonderware inbatchAug 16, 2011

  • CVE-2013-0685
    38Monitor

    Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values,

    CriticalCVSS 9.3No exploitEPSS 3%

    invensys · wonderware information serverMay 9, 2013

  • CVE-2013-0686
    38Monitor

    Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to read arbitrary files, send

    CriticalCVSS 9.3No exploitEPSS 2%

    invensys · wonderware information serverMay 9, 2013

  • CVE-2012-4710
    38Monitor

    Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, o

    CriticalCVSS 9.3No exploitEPSS 2%

    invensys · wonderware win-xml exporterApr 4, 2013

  • CVE-2012-0228
    31Monitor

    Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass

    HighCVSS 7.5No exploitEPSS 2%

    invensys · wonderware information serverApr 2, 2012

  • CVE-2012-0226
    31Monitor

    SQL injection vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to execute arbitrary SQL comma

    HighCVSS 7.5No exploitEPSS 2%

    invensys · wonderware information serverApr 2, 2012

  • CVE-2014-2380
    31Monitor

    Schneider Electric Wonderware Inadequate Encryption Strength

    HighCVSS 7.8No exploitEPSS 1%

    invensys · wonderware information serverAug 27, 2014

  • CVE-2014-5399
    30Monitor

    Schneider Electric Wonderware SQL Injection

    HighCVSS 7.5No exploitEPSS 2%

    invensys · wonderware information serverAug 27, 2014

  • CVE-2013-0684
    30Monitor

    SQL injection vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers

    HighCVSS 7.5No exploitEPSS 1%

    invensys · wonderware information serverMay 9, 2013

  • CVE-2012-0258
    28Monitor

    Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 20

    MediumCVSS 6.8No exploitEPSS 3%

    invensys · archestra application object toolkitApr 2, 2012

  • CVE-2012-0257
    28Monitor

    Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 20

    MediumCVSS 6.8No exploitEPSS 3%

    invensys · archestra application object toolkitApr 2, 2012

  • CVE-2011-4870
    28Monitor

    Multiple buffer overflows in the (1) GUIControls, (2) BatchObjSrv, and (3) BatchSecCtrl ActiveX controls in Invensys Wonderware InBatch 9.0

    MediumCVSS 6.8No exploitEPSS 2%

    invensys · wonderware inbatchJan 7, 2012

  • CVE-2012-4709
    27Monitor

    Invensys Wonderware InTouch HMI 2012 R2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers,

    MediumCVSS 6.9No exploitEPSS 1%

    invensys · wonderware intouchOct 13, 2013

  • CVE-2012-3005
    27Monitor

    Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware In

    MediumCVSS 6.9No exploitEPSS 0%

    invensys · foxboro control softwareJul 26, 2012

  • CVE-2012-3007
    21Monitor

    Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as us

    MediumCVSS 5.0No exploitEPSS 2%

    invensys · dasabcipJul 4, 2012

  • CVE-2012-3847
    20Monitor

    slssvc.exe in Invensys Wonderware SuiteLink in Invensys InTouch 2012 and Wonderware Application Server 2012 allows remote attackers to cause

    MediumCVSS 5.0No exploitEPSS 1%

    invensys · intouchJul 4, 2012

  • CVE-2011-4038
    18Monitor

    Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream R

    MediumCVSS 4.3No exploitEPSS 2%

    invensys · wonderware hmi reportsFeb 10, 2012

  • CVE-2014-5397
    17Monitor

    Schneider Electric Wonderware Cross-site Scripting

    MediumCVSS 4.3No exploitEPSS 2%

    invensys · wonderware information serverAug 27, 2014

  • CVE-2012-0225
    17Monitor

    Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to inject arbitra

    MediumCVSS 4.3No exploitEPSS 2%

    invensys · wonderware information serverApr 2, 2012

  • CVE-2013-0688
    17Monitor

    Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows rem

    MediumCVSS 4.3No exploitEPSS 1%

    invensys · wonderware information serverMay 9, 2013

  • Schneider Electric Wonderware Input Validation

    LowCVSS 2.1No exploitEPSS 1%

    invensys · wonderware information serverAug 27, 2014