ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-8840
A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versi

A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, alarm, or event related action such as read and write, which may allow remote code execution.

NVD description · AI analysis pending
9.88%
  • indusoft web studio
  • indusoft intouch machine edition 2017
CVE-2014-0780
Directory Traversal in InduSoft Web Studio NTWebServer Enables Password Theft and RCE

InduSoft Web Studio's bundled NTWebServer component contains a directory traversal flaw (CWE-22) that lets a remote attacker send crafted HTTP requests that escape the web root and read files outside it, including the product's application (APP) files. Because those APP files store administrative passwords, an attacker who harvests them can authenticate to the product and ultimately achieve remote code execution. Any deployment running InduSoft Web Studio with the NTWebServer web service enabled is affected, especially HMI/SCADA servers reachable from untrusted networks or the internet. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-15) and carries a high EPSS score of about 74% (99th percentile), indicating substantial exploitation likelihood, though public PoC code is not known. Ransomware association is not documented.

Do: Apply updates to InduSoft Web Studio per the vendor's instructions, as required by CISA's KEV listing. Until patched, restrict access to NTWebServer from untrusted networks and review web logs for directory traversal request patterns. If compromise is suspected, rotate administrative passwords stored in APP files, since their disclosure enables remote code execution.

74% KEV
  • InduSoft Web Studio
moderatelikely on the order of tens of thousands of installed copies worldwide, with only a subset (internet-exposed NTWebServer instances) directly reachable