Vulnerabilities > Schneider Electric > Wonderware Indusoft WEB Studio

DATE CVE VULNERABILITY TITLE RISK
2017-11-13 CVE-2017-14024 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Schneider-Electric Wonderware Indusoft web Studio and Wonderware Intouch
A Stack-based Buffer Overflow issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 Patch 1 and prior versions, and InTouch Machine Edition v8.0 SP2 Patch 1 and prior versions.
network
low complexity
schneider-electric CWE-119
critical
10.0
2017-10-03 CVE-2017-13997 Missing Authentication for Critical Function vulnerability in Schneider-Electric Wonderware Indusoft web Studio and Wonderware Intouch
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior.
network
low complexity
schneider-electric CWE-306
critical
10.0
2017-05-19 CVE-2017-7968 Incorrect Default Permissions vulnerability in Schneider-Electric Wonderware Indusoft web Studio
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions.
local
low complexity
schneider-electric CWE-276
7.2