InduSoft kayıtları
indusoft üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %8,3
- Silahlaştırılmış
- 4 · %33,3
- Pre-auth RCE
- 10
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 2912 gün
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-20 Improper Input Validation2
- CWE-121 Stack-based Buffer Overflow1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
91Hemen | CVE-2014-0780Silahlaştırılmış | InduSoft Web Studio Path Traversalindusoft · web studio · CWE-22 | Kritik9,8 | KEV | %74,7 | 25 Nis 2014 |
61Bu hafta | CVE-2011-4051Silahlaştırılmış | CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which indusoft · web studio · CWE-287 | Kritik10,0 | — | %69,1 | 5 Ara 2011 |
50Planlayın | CVE-2011-1900Silahlaştırılmış | Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arindusoft · web studio · CWE-22 | Kritik10,0 | — | %32,0 | 4 May 2011 |
47Planlayın | CVE-2011-0340Silahlaştırılmış | Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as dadvantech · advantech studio · CWE-119 | Kritik9,3 | — | %32,3 | 4 May 2011 |
43Planlayın | CVE-2011-0488İstismar yok | Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and Iadvantech · advantech studio · CWE-119 | Kritik10,0 | — | %8,6 | 18 Oca 2011 |
42Planlayın | CVE-2018-8840İstismar yok | A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 indusoft · web studio · CWE-121 | Kritik9,8 | — | %8,6 | 18 Nis 2018 |
42Planlayın | CVE-2011-0342İstismar yok | Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01indusoft · web studio · CWE-119 | Kritik10,0 | — | %5,9 | 2 Eyl 2011 |
39İzleyin | CVE-2011-4052İstismar yok | Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows rindusoft · web studio · CWE-119 | Kritik9,3 | — | %5,7 | 5 Ara 2011 |
32İzleyin | CVE-2013-1627Kavram kanıtı | Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remoadvantech · advantech studio · CWE-22 | Yüksek7,8 | — | %3,4 | 11 Mar 2013 |
31İzleyin | CVE-2015-7374İstismar yok | The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspecindusoft · web studio · CWE-20 | Yüksek7,5 | — | %2,9 | 25 Eyl 2015 |
31İzleyin | CVE-2015-7375İstismar yok | Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled indusoft · web studio · CWE-20 | Yüksek7,5 | — | %2,2 | 25 Eyl 2015 |
6İzleyin | CVE-2015-1009İstismar yok | Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext findusoft · web studio · CWE-200 | Düşük1,7 | — | %0,3 | 31 Tem 2015 |
- CVE-2014-078091Hemen
InduSoft Web Studio Path Traversal
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %75indusoft · web studio25 Nis 2014
- CVE-2011-405161Bu hafta
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which
KritikCVSS 10,0SilahlaştırılmışEPSS %69indusoft · web studio5 Ara 2011
- CVE-2011-190050Planlayın
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute ar
KritikCVSS 10,0SilahlaştırılmışEPSS %32indusoft · web studio4 May 2011
- CVE-2011-034047Planlayın
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as d
KritikCVSS 9,3SilahlaştırılmışEPSS %32advantech · advantech studio4 May 2011
- CVE-2011-048843Planlayın
Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and I
KritikCVSS 10,0İstismar yokEPSS %9advantech · advantech studio18 Oca 2011
- CVE-2018-884042Planlayın
A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017
KritikCVSS 9,8İstismar yokEPSS %9indusoft · web studio18 Nis 2018
- CVE-2011-034242Planlayın
Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01
KritikCVSS 10,0İstismar yokEPSS %6indusoft · web studio2 Eyl 2011
- CVE-2011-405239İzleyin
Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows r
KritikCVSS 9,3İstismar yokEPSS %6indusoft · web studio5 Ara 2011
- CVE-2013-162732İzleyin
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remo
YüksekCVSS 7,8Kavram kanıtıEPSS %3advantech · advantech studio11 Mar 2013
- CVE-2015-737431İzleyin
The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspec
YüksekCVSS 7,5İstismar yokEPSS %3indusoft · web studio25 Eyl 2015
- CVE-2015-737531İzleyin
Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled
YüksekCVSS 7,5İstismar yokEPSS %2indusoft · web studio25 Eyl 2015
- CVE-2015-10096İzleyin
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext f
DüşükCVSS 1,7İstismar yokEPSS %0indusoft · web studio31 Tem 2015