First published: Thu Apr 04 2013(Updated: )
Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Invensys Wonderware Win-XML Exporter | =1522.148.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4710 is considered a medium to high severity vulnerability due to its potential for remote exploitation and impact on system resources.
To remediate CVE-2012-4710, users should upgrade to a patched version of Invensys Wonderware Win-XML Exporter that addresses this vulnerability.
CVE-2012-4710 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service.
CVE-2012-4710 specifically affects Invensys Wonderware Win-XML Exporter version 1522.148.0.0.
Exploiting CVE-2012-4710 can lead to unauthorized access to files, disruption of service, and increased CPU and memory consumption.