// For flags

CVE-2012-3005

 

Severity Score

6.9
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and Wonderware Historian, allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

Una vulnerabilidad de ruta de búsqueda no confiable en Invensys Wonderware InTouch 2012 y anteriores, tal como se utiliza en el servidor de aplicaciones Wonderware, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch y Wonderware Historian, permite a usuarios locales conseguir privilegios a través de un DLL troyano en un directorio no especificado.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-05-30 CVE Reserved
  • 2012-07-26 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Invensys
Search vendor "Invensys"
Foxboro Control Software
Search vendor "Invensys" for product "Foxboro Control Software"
3.1
Search vendor "Invensys" for product "Foxboro Control Software" and version "3.1"
-
Affected
Invensys
Search vendor "Invensys"
Foxboro Control Software
Search vendor "Invensys" for product "Foxboro Control Software"
4.0
Search vendor "Invensys" for product "Foxboro Control Software" and version "4.0"
-
Affected
Invensys
Search vendor "Invensys"
Infusion Ce\/fe\/scada
Search vendor "Invensys" for product "Infusion Ce\/fe\/scada"
<= 2.5
Search vendor "Invensys" for product "Infusion Ce\/fe\/scada" and version " <= 2.5"
-
Affected
Invensys
Search vendor "Invensys"
Intouch
Search vendor "Invensys" for product "Intouch"
<= 2012
Search vendor "Invensys" for product "Intouch" and version " <= 2012"
-
Affected
Invensys
Search vendor "Invensys"
Intouch\/wonderware Application Server
Search vendor "Invensys" for product "Intouch\/wonderware Application Server"
<= 2012
Search vendor "Invensys" for product "Intouch\/wonderware Application Server" and version " <= 2012"
-
Affected
Invensys
Search vendor "Invensys"
Intouch\/wonderware Application Server
Search vendor "Invensys" for product "Intouch\/wonderware Application Server"
10.0
Search vendor "Invensys" for product "Intouch\/wonderware Application Server" and version "10.0"
-
Affected
Invensys
Search vendor "Invensys"
Intouch\/wonderware Application Server
Search vendor "Invensys" for product "Intouch\/wonderware Application Server"
10.5
Search vendor "Invensys" for product "Intouch\/wonderware Application Server" and version "10.5"
-
Affected
Invensys
Search vendor "Invensys"
Wonderware Historian
Search vendor "Invensys" for product "Wonderware Historian"
<= 10.0
Search vendor "Invensys" for product "Wonderware Historian" and version " <= 10.0"
sp1
Affected
Invensys
Search vendor "Invensys"
Wonderware Historian
Search vendor "Invensys" for product "Wonderware Historian"
10.0
Search vendor "Invensys" for product "Wonderware Historian" and version "10.0"
-
Affected
Invensys
Search vendor "Invensys"
Wonderware Inbatch
Search vendor "Invensys" for product "Wonderware Inbatch"
<= 9.5
Search vendor "Invensys" for product "Wonderware Inbatch" and version " <= 9.5"
sp1
Affected
Invensys
Search vendor "Invensys"
Wonderware Information Server
Search vendor "Invensys" for product "Wonderware Information Server"
<= 4.5
Search vendor "Invensys" for product "Wonderware Information Server" and version " <= 4.5"
-
Affected
Invensys
Search vendor "Invensys"
Wonderware Information Server
Search vendor "Invensys" for product "Wonderware Information Server"
3.1
Search vendor "Invensys" for product "Wonderware Information Server" and version "3.1"
-
Affected
Invensys
Search vendor "Invensys"
Wonderware Information Server
Search vendor "Invensys" for product "Wonderware Information Server"
4.0
Search vendor "Invensys" for product "Wonderware Information Server" and version "4.0"
-
Affected
Invensys
Search vendor "Invensys"
Wonderware Information Server
Search vendor "Invensys" for product "Wonderware Information Server"
4.0
Search vendor "Invensys" for product "Wonderware Information Server" and version "4.0"
sp1
Affected