Invensys occupies a specialized position in industrial automation and process-control software, with a focused product portfolio spanning supervisory and human-machine-interface systems such as Wonderware Information Server, Application Server, and InTouch, as well as control-station software for critical manufacturing and utility operations. The vulnerability surface reflects the integration-heavy, networked character of these systems: the recurring weakness classes center on memory-safety issues including buffer-boundary violations, combined with input-handling flaws such as cross-site scripting, SQL injection, and improper validation that arise in web-facing administrative interfaces and data-integration layers. Because these products often operate in environments where uptime and change-control constraints complicate patching, defenders should track Invensys advisories as high-priority for any exposed instances and maintain inventory of deployed versions. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Invensys over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4557HIGH Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series Batch 8.1 and possibly other products, allows remote attack | Dec 17, 2010 | 10.0 | 46 | NO | YES |
CVE-2010-2974HIGH Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control in Wonderware Application Server | Aug 5, 2010 | 9.3 | 29 | NO | NO |
CVE-2012-4710HIGH Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and mem | Apr 4, 2013 | 9.3 | 28 | NO | NO |
CVE-2011-4039HIGH Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execut | Feb 10, 2012 | 9.3 | 28 | NO | NO |
CVE-2011-3141HIGH Buffer overflow in the InBatch BatchField ActiveX control for Invensys Wonderware InBatch 8.1 SP1, 9.0, and 9.0 SP1 allows remote attackers to cause a denial of service (crash) and | Aug 16, 2011 | 9.3 | 28 | NO | NO |
CVE-2011-2962HIGH Multiple stack-based buffer overflows in Invensys Wonderware Information Server 3.1, 4.0, and 4.0 SP1 allow remote attackers to cause a denial of service (crash) and possibly execu | Jul 29, 2011 | 9.3 | 27 | NO | NO |
CVE-2013-0686HIGH Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or ca | May 9, 2013 | 9.3 | 26 | NO | NO |
CVE-2014-5399HIGH SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspe | Aug 28, 2014 | 7.5 | 25 | NO | NO |
CVE-2014-2380HIGH Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a c | Aug 28, 2014 | 7.8 | 25 | NO | NO |
CVE-2013-0685HIGH Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values, which allows remote attackers to execute | May 9, 2013 | 9.3 | 24 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Invensys.
Media articles that mention a CVE ID that affects a product developed by Invensys — matched by CVE ID, not by vendor name.