Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Indusoft

First CVE: Jan 18, 2011Active for: 16 yearsTotal CVEs: 12
80.7
VTI Score
TOP TARGET

Indusoft develops industrial automation and human-machine interface (HMI) software, including Web Studio and Thin Client products that are deployed in operational technology environments where vulnerability exposure can affect production systems. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, a moderate tendency toward confirmed in-the-wild exploitation, and a strong track record of public exploit availability. The exposure recurs through memory-safety and input-handling weakness classes—including buffer boundary violations, path traversal, improper input validation, and authentication flaws—that are characteristic of industrial control software and reflect the complexity of parsing untrusted network input in resource-constrained embedded contexts. Defenders should prioritize patches for internet-facing or networked instances of these products; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
8.6
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
8.3%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Indusoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2011
15 years ago
Most Recent CVE
Apr 18, 2018
3,019 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-0780CRITICAL
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequent
Apr 25, 20149.895YESYES
CVE-2011-4051HIGH
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbit
Dec 5, 201110.083NOYES
CVE-2011-0340HIGH
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 6
May 4, 20119.364NOYES
CVE-2011-1900HIGH
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arbitrary code via an invalid request.
May 4, 201110.058NOYES
CVE-2018-8840CRITICAL
A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, al
Apr 18, 20189.834NONO
CVE-2013-1627HIGH
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via
Mar 11, 20137.830NOYES
CVE-2011-0342HIGH
Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01.04 allow remote attackers to execute ar
Sep 2, 201110.030NONO
CVE-2011-0488HIGH
Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft Web Studio 7.0, allows remote at
Jan 18, 201110.030NONO
CVE-2011-4052HIGH
Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote attackers to execute arbitrary cod
Dec 5, 20119.328NONO
CVE-2015-7375HIGH
Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime exception and application crash)
Sep 25, 20157.520NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
8%
75%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowHighCritical
Attack Vector
Local0 (0.0%)
Network2 (16.7%)
Unknown10 (83.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (16.7%)
High0 (0.0%)
Unknown10 (83.3%)
User Interaction
None2 (16.7%)
Unknown10 (83.3%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (16.7%)
Unknown10 (83.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
1 CVE
8.3% of CVEs· 100th percentile
Metasploit
3 CVEs
25.0% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
33.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Indusoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Indusoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Indusoft's Products

View all 3 CNAs →

Top CWEs