CVE-2012-0228: High severity wonderware information server vulnerability
Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0228?
CVE-2012-0228 is considered a critical vulnerability due to its ability to allow remote access that bypasses security controls.
How do I fix CVE-2012-0228?
To fix CVE-2012-0228, update to the latest version of Invensys Wonderware Information Server that includes security patches.
Which versions of Invensys Wonderware Information Server are affected by CVE-2012-0228?
CVE-2012-0228 affects Invensys Wonderware Information Server versions 4.0 SP1 and 4.5.
What types of attacks can exploit CVE-2012-0228?
CVE-2012-0228 can be exploited through unauthorized remote access, potentially allowing attackers to manipulate server operations.
Is there a workaround available for CVE-2012-0228 until a patch is applied?
Although there are no official workarounds, it is advised to limit network exposure of the affected systems until a patch is applied.