Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers, and possibly anonymous users, to execute arbitrary programs.
References
Configurations
Information
Published : 2007-11-19 18:46
Updated : 2008-11-14 21:00
NVD link : CVE-2007-6033
Mitre link : CVE-2007-6033
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
wonderware
- intouch