Back

HIGH

Schneider Electric Wonderware InTouch Access Anywhere Server Buffer Overflow

Published Jan 10, 2015

Description

Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote attackers to execute arbitrary code via a request for a filename that does not exist.

Affected products

Remediation

Vendor solution

Schneider Electric has released a security update that mitigates the stack-based buffer overflow vulnerability in Wonderware’s InTouch Access Anywhere Server product, Versions 10.6 and 11.0. Schneider Electric’s security updates for Version 10.6 and Version 11.0 are available at the following location with a user account:

https://wdnresource.wonderware.com/tracking/confirmdownload.aspx?id=3001&url=https://wdnresource... https://wdnresource.wonderware.com/tracking/confirmdownload.aspx

Schneider Electric has released a security bulletin titled “InTouch Access Anywhere Server Security Vulnerability, LFSEC00000104” to announce the security update, which is available at the following location:

https://gcsresource.invensys.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000104.pdf

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jan 10, 2015
Updated Jul 24, 2025
Reserved Dec 2, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a