CVE-2007-6033

Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers, and possibly anonymous users, to execute arbitrary programs.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wonderware:intouch:8.0:*:*:*:*:*:*:*

History

25 Jan 2024, 21:37

Type Values Removed Values Added
CVSS v2 : 9.0
v3 : unknown
v2 : 9.0
v3 : 8.8
References (SECUNIA) http://secunia.com/advisories/27751 - Vendor Advisory (SECUNIA) http://secunia.com/advisories/27751 - Broken Link, Vendor Advisory
References (CONFIRM) http://pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsThreadID=2&NewsID=201804 - (CONFIRM) http://pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsThreadID=2&NewsID=201804 - Broken Link
References (OSVDB) http://osvdb.org/42398 - (OSVDB) http://osvdb.org/42398 - Broken Link
References (MISC) http://www.digitalbond.com/index.php/2007/11/19/wonderware-intouch-80-netdde-vulnerability-s4-preview/ - (MISC) http://www.digitalbond.com/index.php/2007/11/19/wonderware-intouch-80-netdde-vulnerability-s4-preview/ - Not Applicable
References (CERT-VN) http://www.kb.cert.org/vuls/id/138633 - US Government Resource (CERT-VN) http://www.kb.cert.org/vuls/id/138633 - Third Party Advisory, US Government Resource
References (BID) http://www.securityfocus.com/bid/26496 - (BID) http://www.securityfocus.com/bid/26496 - Broken Link, Third Party Advisory, VDB Entry
CWE CWE-264 CWE-732

Information

Published : 2007-11-20 02:46

Updated : 2024-02-28 11:01


NVD link : CVE-2007-6033

Mitre link : CVE-2007-6033

CVE.ORG link : CVE-2007-6033


JSON object : View

Products Affected

wonderware

  • intouch
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource