CVE-2017-5156 describes a Cross-Site Request Forgery (CSRF) vulnerability in Schneider Electric Wonderware InTouch Access Anywhere, versions 11.5.2 and prior. This flaw allows an attacker to forge client requests from a different site, enabling unauthorized access to internal RDP systems on behalf of a logged-in user. With a CVSS score of 8.8 (HIGH), the vulnerability is easily exploitable over a network with low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. While no public exploits are available in Metasploit or ExploitDB, and it is not listed in the KEV catalog, it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.5.2CPE matchmatch criteria | cpe:2.3:a:aveva:wonderware_intouch_access_anywhere:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.