Vulnerabilities > Indusoft > WEB Studio > 7.1

DATE CVE VULNERABILITY TITLE RISK
2018-04-18 CVE-2018-8840 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, alarm, or event related action such as read and write, which may allow remote code execution.
network
low complexity
indusoft industrial-software CWE-119
critical
10.0
2015-09-25 CVE-2015-7375 Improper Input Validation vulnerability in Indusoft web Studio 6.1/7.0/7.1
Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime exception and application crash) via a crafted Indusoft Project file.
network
low complexity
indusoft CWE-20
7.5
2015-09-25 CVE-2015-7374 Improper Input Validation vulnerability in Indusoft web Studio 6.1/7.0/7.1
The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-2649.
network
low complexity
indusoft CWE-20
7.5
2015-08-01 CVE-2015-1009 Information Exposure vulnerability in multiple products
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file.
local
low complexity
indusoft wonderware CWE-200
1.7
2014-04-25 CVE-2014-0780 Path Traversal vulnerability in Indusoft web Studio 7.1
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.
network
low complexity
indusoft CWE-22
7.5