Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2012-4709

EPSS 0.15% · P35
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2012-4709

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Invensys Wonderware InTouch HMI 2012 R2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Invensys Wonderware InTouch XML外部实体注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Invensys Wonderware InTouch是英国英维思(Invensys)公司的一套开放的、可扩展的HMI和SCADA监控解决方案。该解决方案可创建标准化的、可重复使用的可视化应用程序。 Invensys Wonderware InTouch HMI 2012 R2及之前的版本中存在XML外部实体注入漏洞。远程攻击者可借助包含外部实体声明和实体引用结合的XML文档利用该漏洞读取任意文件,发送HTTP请求到内部服务器,或造成拒绝服务(CPU和内存耗尽)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2012-4709

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2012-4709

登录查看更多情报信息。

Same Patch Batch · n/a · 2013-10-13 · 25 CVEs total

CVE-2013-4825HP IMC和IMC Service Operation Management Software Module 安全绕过漏洞
CVE-2013-5515Cisco ASA软件Clientless SSL VPN功能拒绝服务漏洞
CVE-2013-5513Cisco ASA软件DNS Application Layer Protocol Inspection引擎拒绝服务漏洞
CVE-2013-5512Cisco ASA软件HTTP Deep Packet Inspection功能拒绝服务漏洞
CVE-2013-5511Cisco ASA软件Adaptive Security Device Management远程管理功能安全绕过漏洞
CVE-2013-5510Cisco ASA软件remote-access VPN 安全绕过漏洞
CVE-2013-5509Cisco ASA软件SSL实现安全绕过漏洞
CVE-2013-5508Cisco ASA和FWSM SQL*Net检查引擎拒绝服务漏洞
CVE-2013-5507Cisco Adaptive Security Appliances Software 加密问题漏洞
CVE-2013-5506Cisco FWSM 身份验证功能安全漏
CVE-2013-4827HP IMC和IMC Service Operation Management Software Module SQL注入漏洞
CVE-2013-4826HP IMC和IMC Service Operation Management Software Module 安全漏洞
CVE-2012-4105Cisco Unified Computing System fabric-interconnect组件拒绝服务漏洞
CVE-2013-4824HP IMC和IMC Service Operation Management Software Module 安全漏洞
CVE-2013-4823HP IMC和IMC BIMS 安全漏洞
CVE-2013-4822HP IMC和IMC BIMS 任意代码执行漏洞
CVE-2013-4804HP Business Process Monitor 远程任意代码执行漏洞和信息泄露漏洞
CVE-2013-4056IBM InfoSphere Information Server 跨站请求伪造漏洞
CVE-2013-3415Cisco ASA软件拒绝服务漏洞
CVE-2013-2787Alstom e-terracontrol软件拒绝服务漏洞

Showing top 20 of 25 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2012-4709

No comments yet


Leave a comment