CVE Vulnerabilities

CVE-2012-3005

Published: Jul 26, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and Wonderware Historian, allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

Affected Software

NameVendorStart VersionEnd Version
Foxboro_control_softwareInvensys3.1 (including)3.1 (including)
Foxboro_control_softwareInvensys4.0 (including)4.0 (including)
Infusion_ce/fe/scadaInvensys*2.5 (including)
IntouchInvensys*2012 (including)
Intouch/wonderware_application_serverInvensys*2012 (including)
Intouch/wonderware_application_serverInvensys10.0 (including)10.0 (including)
Intouch/wonderware_application_serverInvensys10.5 (including)10.5 (including)
Wonderware_historianInvensys*10.0 (including)
Wonderware_historianInvensys10.0 (including)10.0 (including)
Wonderware_inbatchInvensys*9.5 (including)
Wonderware_information_serverInvensys*4.5 (including)
Wonderware_information_serverInvensys3.1 (including)3.1 (including)
Wonderware_information_serverInvensys4.0 (including)4.0 (including)
Wonderware_information_serverInvensys4.0-sp1 (including)4.0-sp1 (including)

References