CVE-2012-3005
Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and Wonderware Historian, allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
Published:Jul 26, 2012
Last Modified:Apr 11, 2025
EPS:Jul 26, 2012
EPSS Score:0.00074
CVSS Score:6.9
Affected Products
Vendor
Product
Action
Vendor
Invensys
Product
Foxboro Control Software
Invensys
Foxboro Control Software
Vendor
Invensys
Product
Infusion Ce\/fe\/scada
Invensys
Infusion Ce\/fe\/scada
Vendor
Invensys
Product
Intouch
Invensys
Intouch
Vendor
Invensys
Product
Intouch\/wonderware Application Server
Invensys
Intouch\/wonderware Application Server
Vendor
Invensys
Product
Wonderware Historian
Invensys
Wonderware Historian
Vendor
Invensys
Product
Wonderware Inbatch
Invensys
Wonderware Inbatch
Vendor
Invensys
Product
Wonderware Information Server
Invensys
Wonderware Information Server
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
