Vulnerabilities > Indusoft > WEB Studio > 7.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-04-18 | CVE-2018-8840 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, alarm, or event related action such as read and write, which may allow remote code execution. | 10.0 |
2015-09-25 | CVE-2015-7375 | Improper Input Validation vulnerability in Indusoft web Studio 6.1/7.0/7.1 Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime exception and application crash) via a crafted Indusoft Project file. | 7.5 |
2015-09-25 | CVE-2015-7374 | Improper Input Validation vulnerability in Indusoft web Studio 6.1/7.0/7.1 The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-2649. | 7.5 |
2015-08-01 | CVE-2015-1009 | Information Exposure vulnerability in multiple products Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file. | 1.7 |
2014-04-25 | CVE-2014-0780 | Path Traversal vulnerability in Indusoft web Studio 7.1 Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests. | 7.5 |