CVE-2012-4710
critical
CVSS v3
—
CVSS v2
9.3
VIR risk
9.3
Description
Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| invensys | wonderware_win-xml_exporter | 1522.148.0.0 | |
References
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.