CVE-2013-0686: Input Validation
Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0686?
CVE-2013-0686 is categorized as a high severity vulnerability due to its potential for remote file access and denial of service.
How do I fix CVE-2013-0686?
To remediate CVE-2013-0686, upgrade to the latest version of Invensys Wonderware Information Server that addresses the vulnerability.
Which versions of software are affected by CVE-2013-0686?
CVE-2013-0686 affects Invensys Wonderware Information Server versions 4.0 SP1SP1, 4.5, and 5.0.
What types of attacks can be executed using CVE-2013-0686?
Attackers can exploit CVE-2013-0686 to read arbitrary files, send HTTP requests to intranet servers, or cause denial of service.
Is there a workaround for CVE-2013-0686 if immediate patching isn’t possible?
A potential workaround for CVE-2013-0686 includes disabling external entity processing on the affected Invensys Wonderware Information Server.