Записи InduSoft
12 опубликованных записей вендора indusoft.
Профиль для исследователя
- Попали в KEV
- 1 · 8,3 %
- С эксплойтом
- 4 · 33,3 %
- Pre-auth RCE
- 10
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 2912 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-20 Improper Input Validation2
- CWE-121 Stack-based Buffer Overflow1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
91Срочно | CVE-2014-0780Готовый эксплойт | InduSoft Web Studio Path Traversalindusoft · web studio · CWE-22 | Критическая9,8 | KEV | 74,7 % | 25 апр. 2014 г. |
61На этой неделе | CVE-2011-4051Готовый эксплойт | CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which indusoft · web studio · CWE-287 | Критическая10,0 | — | 69,1 % | 5 дек. 2011 г. |
50В плане | CVE-2011-1900Готовый эксплойт | Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arindusoft · web studio · CWE-22 | Критическая10,0 | — | 32,0 % | 4 мая 2011 г. |
47В плане | CVE-2011-0340Готовый эксплойт | Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as dadvantech · advantech studio · CWE-119 | Критическая9,3 | — | 32,3 % | 4 мая 2011 г. |
43В плане | CVE-2011-0488Эксплойта нет | Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and Iadvantech · advantech studio · CWE-119 | Критическая10,0 | — | 8,6 % | 18 янв. 2011 г. |
42В плане | CVE-2018-8840Эксплойта нет | A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 indusoft · web studio · CWE-121 | Критическая9,8 | — | 8,6 % | 18 апр. 2018 г. |
42В плане | CVE-2011-0342Эксплойта нет | Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01indusoft · web studio · CWE-119 | Критическая10,0 | — | 5,9 % | 2 сент. 2011 г. |
39Наблюдать | CVE-2011-4052Эксплойта нет | Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows rindusoft · web studio · CWE-119 | Критическая9,3 | — | 5,7 % | 5 дек. 2011 г. |
32Наблюдать | CVE-2013-1627Proof of concept | Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remoadvantech · advantech studio · CWE-22 | Высокая7,8 | — | 3,4 % | 11 мар. 2013 г. |
31Наблюдать | CVE-2015-7374Эксплойта нет | The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspecindusoft · web studio · CWE-20 | Высокая7,5 | — | 2,9 % | 25 сент. 2015 г. |
31Наблюдать | CVE-2015-7375Эксплойта нет | Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled indusoft · web studio · CWE-20 | Высокая7,5 | — | 2,2 % | 25 сент. 2015 г. |
6Наблюдать | CVE-2015-1009Эксплойта нет | Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext findusoft · web studio · CWE-200 | Низкая1,7 | — | 0,3 % | 31 июл. 2015 г. |
- CVE-2014-078091Срочно
InduSoft Web Studio Path Traversal
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 75 %indusoft · web studio25 апр. 2014 г.
- CVE-2011-405161На этой неделе
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which
КритическаяCVSS 10,0Готовый эксплойтEPSS 69 %indusoft · web studio5 дек. 2011 г.
- CVE-2011-190050В плане
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute ar
КритическаяCVSS 10,0Готовый эксплойтEPSS 32 %indusoft · web studio4 мая 2011 г.
- CVE-2011-034047В плане
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as d
КритическаяCVSS 9,3Готовый эксплойтEPSS 32 %advantech · advantech studio4 мая 2011 г.
- CVE-2011-048843В плане
Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and I
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %advantech · advantech studio18 янв. 2011 г.
- CVE-2018-884042В плане
A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %indusoft · web studio18 апр. 2018 г.
- CVE-2011-034242В плане
Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %indusoft · web studio2 сент. 2011 г.
- CVE-2011-405239Наблюдать
Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows r
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %indusoft · web studio5 дек. 2011 г.
- CVE-2013-162732Наблюдать
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remo
ВысокаяCVSS 7,8Proof of conceptEPSS 3 %advantech · advantech studio11 мар. 2013 г.
- CVE-2015-737431Наблюдать
The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspec
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %indusoft · web studio25 сент. 2015 г.
- CVE-2015-737531Наблюдать
Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %indusoft · web studio25 сент. 2015 г.
- CVE-2015-10096Наблюдать
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext f
НизкаяCVSS 1,7Эксплойта нетEPSS 0 %indusoft · web studio31 июл. 2015 г.