CVE-2012-3005: Medium severity invensys foxboro control software vulnerability
Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and Wonderware Historian, allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3005?
CVE-2012-3005 has a moderate severity rating as it allows local users to gain elevated privileges.
How do I fix CVE-2012-3005?
To fix CVE-2012-3005, implement updates and patches provided by Invensys for the affected software.
What software is impacted by CVE-2012-3005?
CVE-2012-3005 affects various Invensys products including InTouch, Wonderware Application Server, and Wonderware Historian.
Can CVE-2012-3005 be exploited remotely?
CVE-2012-3005 requires local user access to exploit, making remote exploitation less likely.
What types of permissions can an attacker gain through CVE-2012-3005?
An attacker exploiting CVE-2012-3005 can gain elevated privileges, potentially allowing them to execute unauthorized actions.