CVE Tools

Invensys

27 CVEs tracked since 2010. Since Aug 2010, none of them reached CISA KEV.

Invensys CVEs per month

Aug 2010 to Aug 2014. Point at a month, or focus the strip and use the arrow keys.
Invensys CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2010-0810
2010-09null or fewer
2010-10null or fewer
2010-11null or fewer
2010-1210
2011-01null or fewer
2011-02null or fewer
2011-03null or fewer
2011-04null or fewer
2011-05null or fewer
2011-06null or fewer
2011-0710
2011-0810
2011-09null or fewer
2011-10null or fewer
2011-11null or fewer
2011-12null or fewer
2012-0110
2012-0220
2012-03null or fewer
2012-0450
2012-05null or fewer
2012-06null or fewer
2012-0730
2012-08null or fewer
2012-09null or fewer
2012-10null or fewer
2012-11null or fewer
2012-1210
2013-01null or fewer
2013-02null or fewer
2013-03null or fewer
2013-0410
2013-0540
2013-06null or fewer
2013-07null or fewer
2013-08null or fewer
2013-09null or fewer
2013-1010
2013-11null or fewer
2013-12null or fewer
2014-01null or fewer
2014-02null or fewer
2014-03null or fewer
2014-04null or fewer
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-0850

Products

The products that kept showing up in Invensys's monthly top three, with their CVEs summed over those months.

  1. Wonderware Information Server154 months
  2. Wonderware Application Server32 months
  3. Wonderware Inbatch33 months
  4. Archestra Application Object Toolkit21 month
  5. Foxboro Control Software21 month
  6. Intouch21 month
  7. Intouch\/wonderware Application Server21 month
  8. Wonderware Hmi Reports21 month
  9. Wonderware Intouch22 months
  10. Foxboro I\/a Series Batch11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Invensys.

  1. CVE-2014-2380Schneider Electric Wonderware Inadequate Encryption Strength7.8
  2. CVE-2014-2381Schneider Electric Wonderware Inadequate Encryption Strength2.1
  3. CVE-2014-5399Schneider Electric Wonderware SQL Injection7.5
  4. CVE-2014-5398Schneider Electric Wonderware Input Validation2.1
  5. CVE-2014-5397Schneider Electric Wonderware Cross-site Scripting7.5
  6. CVE-2012-4709Invensys Wonderware InTouch HMI 2012 R2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption...6.9
  7. CVE-2013-0684SQL injection vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.7.5
  8. CVE-2013-0688Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to inject arbitrary web script or HTML via ...4.3
  9. CVE-2013-0686Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of s...9.3
  10. CVE-2013-0685Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values, which allows remote attackers to execute arbitrary code o...9.3
  11. CVE-2012-4710Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) ...9.3
  12. CVE-2012-4693Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algorithm for data in Ps_security.ini, which makes it easier for local users to discover passwords by ...1.9
  13. CVE-2012-3005Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/F...6.9
  14. CVE-2012-3847slssvc.exe in Invensys Wonderware SuiteLink in Invensys InTouch 2012 and Wonderware Application Server 2012 allows remote attackers to cause a denial of service (resource consumption) via a long Un...5.0
  15. CVE-2012-3007Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as used in InTouch/Wonderware Application Server IT before 10....5.0

The record

Peak rank
#16 in Apr 2012
Busiest month shown
Apr 2012, 5 CVEs
Months with a KEV entry
0 since Aug 2010
Monthly snapshots
13 since 2010
Invensys's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store