Web Studio

Vendor:

First CVE: Jan 18, 2011 · Active for 15 years

12
Total CVEs
More Total CVEs than 90% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
8.6
Avg CVSS
Higher Avg CVSS than 76% of tracked products
8.3%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Web Studio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2011
15 years ago
Most Recent CVE
Apr 18, 2018
3,020 days ago

CVE Severity & Scoring

Web Studio12 CVEs
All CVEs352,708 CVEs
LowHighCritical
Attack Vector
Local0 (0.0%)
Network2 (16.7%)
Unknown10 (83.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (16.7%)
High0 (0.0%)
Unknown10 (83.3%)
User Interaction
None2 (16.7%)
Unknown10 (83.3%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (16.7%)
Unknown10 (83.3%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequent
Apr 25, 20149.895YESYES
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbit
Dec 5, 201110.083NOYES
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 6
May 4, 20119.364NOYES
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arbitrary code via an invalid request.
May 4, 201110.058NOYES
A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, al
Apr 18, 20189.834NONO
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via
Mar 11, 20137.830NOYES
Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01.04 allow remote attackers to execute ar
Sep 2, 201110.030NONO
Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft Web Studio 7.0, allows remote at
Jan 18, 201110.030NONO
Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote attackers to execute arbitrary cod
Dec 5, 20119.328NONO
Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime exception and application crash)
Sep 25, 20157.520NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
1 CVE
8.3% of CVEs· 97th percentile
Metasploit
3 CVEs
25.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
33.3% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Web Studio

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.119.874.6%11
7.0b228.94.7%01
7.059.423.8%03
6.159.125.5%04