Vulnerability Description
Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Invensys | Wonderware Win-Xml Exporter | 1522.148.0.0 |
Related Weaknesses (CWE)
References
- http://ics-cert.us-cert.gov/pdf/ICSA-13-067-02.pdfUS Government Resource
- http://ics-cert.us-cert.gov/pdf/ICSA-13-067-02.pdfUS Government Resource
FAQ
What is CVE-2012-4710?
CVE-2012-4710 is a vulnerability with a CVSS score of 9.3 (HIGH). Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via...
How severe is CVE-2012-4710?
CVE-2012-4710 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4710?
Check the references section above for vendor advisories and patch information. Affected products include: Invensys Wonderware Win-Xml Exporter.