First published: Mon Apr 02 2012(Updated: )
Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invensys Wonderware Information Server | =4.0-sp1 | |
Invensys Wonderware Information Server | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0228 is considered a critical vulnerability due to its ability to allow remote access that bypasses security controls.
To fix CVE-2012-0228, update to the latest version of Invensys Wonderware Information Server that includes security patches.
CVE-2012-0228 affects Invensys Wonderware Information Server versions 4.0 SP1 and 4.5.
CVE-2012-0228 can be exploited through unauthorized remote access, potentially allowing attackers to manipulate server operations.
Although there are no official workarounds, it is advised to limit network exposure of the affected systems until a patch is applied.