CVE-2012-3005
Description
Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and Wonderware Historian, allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| invensys | foxboro_control_software | 3.1 | |
| invensys | foxboro_control_software | 4.0 | |
| invensys | infusion_ce\/fe\/scada | {"endIncluding":"2.5"} | |
| invensys | intouch | {"endIncluding":"2012"} | |
| invensys | intouch\/wonderware_application_server | {"endIncluding":"2012"} | |
| invensys | intouch\/wonderware_application_server | 10.0 | |
| invensys | intouch\/wonderware_application_server | 10.5 | |
| invensys | wonderware_historian | {"endIncluding":"10.0"} | |
| invensys | wonderware_historian | 10.0 | |
| invensys | wonderware_inbatch | {"endIncluding":"9.5"} | |
| invensys | wonderware_information_server | {"endIncluding":"4.5"} | |
| invensys | wonderware_information_server | 3.1 | |
| invensys | wonderware_information_server | 4.0 | |
References
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.