CVE-2013-0686
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Invensys Wonderware Information Server (WIS) V4.0 SP1SP1, v4.5- Portal, y v5.0- Portal permite a atacantes remotos leer ficheros arbitrarios, enviar peticiones HTTP a servidores de la red interna o causar denegación de servicios (consumo de memoria y CPU) a través de un documento XML que contiene una entidad externa declarada junto con una referencia entidad, relacionado con un asunto XML External Entity (XEE).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-12-19 CVE Reserved
- 2013-05-09 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
http://ics-cert.us-cert.gov/advisories/ICSA-13-113-01 | Us Government Resource |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Invensys Search vendor "Invensys" | Wonderware Information Server Search vendor "Invensys" for product "Wonderware Information Server" | 4.0 Search vendor "Invensys" for product "Wonderware Information Server" and version "4.0" | sp1sp1 |
Affected
| ||||||
Invensys Search vendor "Invensys" | Wonderware Information Server Search vendor "Invensys" for product "Wonderware Information Server" | 4.5 Search vendor "Invensys" for product "Wonderware Information Server" and version "4.5" | portal |
Affected
| ||||||
Invensys Search vendor "Invensys" | Wonderware Information Server Search vendor "Invensys" for product "Wonderware Information Server" | 5.0 Search vendor "Invensys" for product "Wonderware Information Server" and version "5.0" | portal |
Affected
|