Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers, and possibly anonymous users, to execute arbitrary programs.
References
Link | Resource |
---|---|
http://osvdb.org/42398 | Broken Link |
http://pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsThreadID=2&NewsID=201804 | Broken Link |
http://secunia.com/advisories/27751 | Broken Link Vendor Advisory |
http://www.digitalbond.com/index.php/2007/11/19/wonderware-intouch-80-netdde-vulnerability-s4-preview/ | Not Applicable |
http://www.kb.cert.org/vuls/id/138633 | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/26496 | Broken Link Third Party Advisory VDB Entry |
http://osvdb.org/42398 | Broken Link |
http://pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsThreadID=2&NewsID=201804 | Broken Link |
http://secunia.com/advisories/27751 | Broken Link Vendor Advisory |
http://www.digitalbond.com/index.php/2007/11/19/wonderware-intouch-80-netdde-vulnerability-s4-preview/ | Not Applicable |
http://www.kb.cert.org/vuls/id/138633 | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/26496 | Broken Link Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2007-11-20 02:46
Updated : 2025-04-09 00:30
NVD link : CVE-2007-6033
Mitre link : CVE-2007-6033
CVE.ORG link : CVE-2007-6033
JSON object : View
Products Affected
wonderware
- intouch
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource