Indusoft develops industrial automation and human-machine interface (HMI) software, including Web Studio and Thin Client products that are deployed in operational technology environments where vulnerability exposure can affect production systems. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, a moderate tendency toward confirmed in-the-wild exploitation, and a strong track record of public exploit availability. The exposure recurs through memory-safety and input-handling weakness classes—including buffer boundary violations, path traversal, improper input validation, and authentication flaws—that are characteristic of industrial control software and reflect the complexity of parsing untrusted network input in resource-constrained embedded contexts. Defenders should prioritize patches for internet-facing or networked instances of these products; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Indusoft over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0780CRITICAL Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequent | Apr 25, 2014 | 9.8 | 95 | YES | YES |
CVE-2011-4051HIGH CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbit | Dec 5, 2011 | 10.0 | 83 | NO | YES |
CVE-2011-0340HIGH Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 6 | May 4, 2011 | 9.3 | 64 | NO | YES |
CVE-2011-1900HIGH Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arbitrary code via an invalid request. | May 4, 2011 | 10.0 | 58 | NO | YES |
CVE-2018-8840CRITICAL A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, al | Apr 18, 2018 | 9.8 | 34 | NO | NO |
CVE-2013-1627HIGH Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via | Mar 11, 2013 | 7.8 | 30 | NO | YES |
CVE-2011-0342HIGH Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01.04 allow remote attackers to execute ar | Sep 2, 2011 | 10.0 | 30 | NO | NO |
CVE-2011-0488HIGH Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft Web Studio 7.0, allows remote at | Jan 18, 2011 | 10.0 | 30 | NO | NO |
CVE-2011-4052HIGH Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote attackers to execute arbitrary cod | Dec 5, 2011 | 9.3 | 28 | NO | NO |
CVE-2015-7375HIGH Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime exception and application crash) | Sep 25, 2015 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Indusoft.
Media articles that mention a CVE ID that affects a product developed by Indusoft — matched by CVE ID, not by vendor name.