Skip to main content

Vendor/product archive

indusoft / web_studio CVEs

Beta · best-effort

12 CVEs tagged to indusoft / web_studio8 Critical, 3 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2015-7375

Published Sep 25, 2015

Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime exception and application crash…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7374

Published Sep 25, 2015

The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-2649.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1009

Published Aug 1, 2015

Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, whi…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-0780

Published Apr 25, 2014

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequen…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2011-4052

Published Dec 5, 2011

Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote attackers to execute arbitrary co…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4051

Published Dec 5, 2011

CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0342

Published Sep 2, 2011

Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01.04 allow remote attackers to execute a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1900

Published May 4, 2011

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arbitrary code via an invalid request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1