Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers, and possibly anonymous users, to execute arbitrary programs.
References
Link | Resource |
---|---|
http://osvdb.org/42398 | Broken Link |
http://pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsThreadID=2&NewsID=201804 | Broken Link |
http://secunia.com/advisories/27751 | Broken Link Vendor Advisory |
http://www.digitalbond.com/index.php/2007/11/19/wonderware-intouch-80-netdde-vulnerability-s4-preview/ | Not Applicable |
http://www.kb.cert.org/vuls/id/138633 | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/26496 | Broken Link Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2007-11-20T02:00:00
Updated: 2007-11-28T10:00:00
Reserved: 2007-11-19T00:00:00
Link: CVE-2007-6033
JSON object: View
NVD Information
Status : Analyzed
Published: 2007-11-20T02:46:00.000
Modified: 2024-01-25T21:37:04.507
Link: CVE-2007-6033
JSON object: View
Redhat Information
No data.
CWE