Schneider Electric Wonderware Vulnerabilities
Schneider Electric Wonderware Information Server Portal versions 4.0_SP1, 4.5, 5.0, and 5.5 contain multiple input validation and encoding flaws (CWE-326, CWE-79, CWE-20, CWE-89). These weaknesses allow remote attackers to inject SQL commands and JavaScript code without authentication, potentially leading to unauthorized data access, data manipulation, cross-site scripting attacks, and compromise of process information displayed to operators. The vulnerabilities exist in the portal's handling of user-supplied input and cryptographic implementations.
- Network access to the Wonderware Information Server Portal web interface
- No authentication required to exploit the vulnerability
- Ability to send crafted HTTP requests to the portal
Patching may require device reboot — plan for process interruption
/api/v1/advisories/05f977ff-4f34-4cf8-9fc9-6ea3cac0fb8dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.