PT-2007-6950 · Invensys · Invensys Wonderware Intouch
CVE-2007-6033
·
Publicado
2007-11-20
·
Atualizado
2024-01-25
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Invensys Wonderware InTouch version 8.0
Description
The issue allows remote authenticated attackers, and possibly anonymous users, to execute arbitrary programs due to insecure permissions set on a NetDDE share.
Recommendations
For Invensys Wonderware InTouch version 8.0, consider restricting access to the NetDDE share to prevent unauthorized execution of programs until a patch is available.
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Invensys Wonderware Intouch