Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and Wonderware Historian, allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
2012-07-26T10:41:47.747
2025-04-11T00:51:21.963
Deferred
CVSSv2: 6.9 (MEDIUM)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | invensys | foxboro_control_software | 3.1 | Yes |
| Application | invensys | foxboro_control_software | 4.0 | Yes |
| Application | invensys | infusion_ce\/fe\/scada | ≤ 2.5 | Yes |
| Application | invensys | intouch | ≤ 2012 | Yes |
| Application | invensys | intouch\/wonderware_application_server | ≤ 2012 | Yes |
| Application | invensys | intouch\/wonderware_application_server | 10.0 | Yes |
| Application | invensys | intouch\/wonderware_application_server | 10.5 | Yes |
| Application | invensys | wonderware_historian | ≤ 10.0 | Yes |
| Application | invensys | wonderware_historian | 10.0 | Yes |
| Application | invensys | wonderware_inbatch | ≤ 9.5 | Yes |
| Application | invensys | wonderware_information_server | ≤ 4.5 | Yes |
| Application | invensys | wonderware_information_server | 3.1 | Yes |
| Application | invensys | wonderware_information_server | 4.0 | Yes |
| Application | invensys | wonderware_information_server | 4.0 | Yes |