PT-2013-1709 · Invensys · Invensys Wonderware Win-Xml Exporter

Aleksey Osipov

+2

·

Publicado

2013-04-04

·

Atualizado

2013-04-04

·

CVE-2012-4710

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Invensys Wonderware Win-XML Exporter version 1522.148.0.0
Description The issue allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service through CPU and memory consumption. This is achieved via an XML external entity declaration in conjunction with an entity reference.
Recommendations For Invensys Wonderware Win-XML Exporter version 1522.148.0.0, consider disabling XML external entity processing as a temporary workaround until a patch is available. Restrict access to sensitive files and intranet servers to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-4710

Produtos afetados

Invensys Wonderware Win-Xml Exporter