Back

CRITICAL KEV

InduSoft Web Studio Path Traversal

Published Apr 25, 2014 ·Due May 6, 2022

Description

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.

Affected products

Remediation

Vendor solution

InduSoft did not intend for this web server to be used in real applications. It was provided as demonstration/training software (as stated in user manuals). They have created a mitigation for this vulnerability in InduSoft Web Studio v7.1+Service Pack 2+ Patch 4. Users may obtain this patch at the following location (you must be logged into your InduSoft account):  http://download.indusoft.com/71.2.4/IWS71.2.4.zip

InduSoft technical support can be contacted at: support@indusoft.com .

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Apr 25, 2014
Updated Oct 22, 2025
Reserved Jan 2, 2014
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a