Wonderware Information Server Vulnerabilities
Wonderware Information Server contains multiple input validation vulnerabilities in its web interface that allow SQL injection, cross-site scripting (XSS), and improper input handling. These flaws exist in the portal and web components across versions 4.0 SP1SP1, 4.5 Portal, and 5.0 Portal. An attacker can exploit these vulnerabilities by submitting malicious input through web-based forms to inject SQL commands or execute scripts, potentially accessing or modifying sensitive industrial process data and system configurations stored in the information server database.
- Network access to Wonderware Information Server web interface (typically port 80 or 443)
- No authentication required for exploitation of input validation flaws
Patching may require device reboot — plan for process interruption
/api/v1/advisories/666b76b1-c0fb-4308-9ef2-d8b3830ad0ddGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.