Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers, and possibly anonymous users, to execute arbitrary programs.
References
Link | Resource |
---|---|
http://osvdb.org/42398 | Broken Link |
http://pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsThreadID=2&NewsID=201804 | Broken Link |
http://secunia.com/advisories/27751 | Broken Link Vendor Advisory |
http://www.digitalbond.com/index.php/2007/11/19/wonderware-intouch-80-netdde-vulnerability-s4-preview/ | Not Applicable |
http://www.kb.cert.org/vuls/id/138633 | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/26496 | Broken Link Third Party Advisory VDB Entry |
http://osvdb.org/42398 | Broken Link |
http://pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsThreadID=2&NewsID=201804 | Broken Link |
http://secunia.com/advisories/27751 | Broken Link Vendor Advisory |
http://www.digitalbond.com/index.php/2007/11/19/wonderware-intouch-80-netdde-vulnerability-s4-preview/ | Not Applicable |
http://www.kb.cert.org/vuls/id/138633 | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/26496 | Broken Link Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 00:39
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/42398 - Broken Link | |
References | () http://pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsThreadID=2&NewsID=201804 - Broken Link | |
References | () http://secunia.com/advisories/27751 - Broken Link, Vendor Advisory | |
References | () http://www.digitalbond.com/index.php/2007/11/19/wonderware-intouch-80-netdde-vulnerability-s4-preview/ - Not Applicable | |
References | () http://www.kb.cert.org/vuls/id/138633 - Third Party Advisory, US Government Resource | |
References | () http://www.securityfocus.com/bid/26496 - Broken Link, Third Party Advisory, VDB Entry |
25 Jan 2024, 21:37
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 9.0
v3 : 8.8 |
References | (SECUNIA) http://secunia.com/advisories/27751 - Broken Link, Vendor Advisory | |
References | (CONFIRM) http://pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsThreadID=2&NewsID=201804 - Broken Link | |
References | (OSVDB) http://osvdb.org/42398 - Broken Link | |
References | (MISC) http://www.digitalbond.com/index.php/2007/11/19/wonderware-intouch-80-netdde-vulnerability-s4-preview/ - Not Applicable | |
References | (CERT-VN) http://www.kb.cert.org/vuls/id/138633 - Third Party Advisory, US Government Resource | |
References | (BID) http://www.securityfocus.com/bid/26496 - Broken Link, Third Party Advisory, VDB Entry | |
CWE | CWE-732 |
Information
Published : 2007-11-20 02:46
Updated : 2024-11-21 00:39
NVD link : CVE-2007-6033
Mitre link : CVE-2007-6033
CVE.ORG link : CVE-2007-6033
JSON object : View
Products Affected
wonderware
- intouch
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource