Vulnerabilities
Vulnerable Software
Indusoft:  >> Web Studio  >> 7.1  Security Vulnerabilities
A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, alarm, or event related action such as read and write, which may allow remote code execution.
CVSS Score
9.8
EPSS Score
0.353
Published
2018-04-18
Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime exception and application crash) via a crafted Indusoft Project file.
CVSS Score
7.5
EPSS Score
0.013
Published
2015-09-25
The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-2649.
CVSS Score
7.5
EPSS Score
0.014
Published
2015-09-25
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file.
CVSS Score
1.7
EPSS Score
0.001
Published
2015-08-01
CVE-2014-0780
Known exploited
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.
CVSS Score
9.8
EPSS Score
0.914
Published
2014-04-25


Contact Us

Shodan ® - All rights reserved