Overview
Invensys Wonderware InTouch 8.0 creates a NetDDE share that could allow an attacker to run arbitrary programs.
Description
Invensys Wonderware InTouch HMI Software is used in Supervisory Control And Data Acquisition (SCADA) systems. Dynamic Data Exchange (DDE) was designed to allow Microsoft Windows applications to share data. NetDDE is an extension to DDE that was developed by Wonderware. NetDDE allows communications with local DDE applications and with remote NetDDE agents using NetBIOS. NetDDE is not supported in Windows Vista, but is included in Windows NT, 2000, XP, and Server 2003. |
Impact
A remote attacker may be able to execute any application that accepts NetDDE connections. This could allow an attacker to gain control of the system running NetDDE |
Solution
Upgrade |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- |
Temporal | 0 | E:ND/RL:ND/RC:ND |
Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- http://us.wonderware.com/aboutus/whoweare/contactus.htm
- http://pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsThreadID=2&NewsID=201804
- http://blogs.msdn.com/nickkramer/archive/2006/04/18/577962.aspx
- http://msdn2.microsoft.com/en-us/library/ms648711.aspx
- http://support.microsoft.com/default.aspx?scid=kb;en-us;125703
- http://lists.immunitysec.com/pipermail/dailydave/2004-October/001014.html
- http://www.digitalbond.com/index.php/2007/11/19/wonderware-intouch-80-netdde-vulnerability-s4-preview/
- http://secunia.com/advisories/27751/
- http://www.digitalbond.com/index.php/2008/01/29/vulnerable-netdde-shares-lead-to-complete-system-compromise/
- http://www.digitalbond.com/wiki/index.php/Invensys_Wonderware_InTouch_creates_insecure_NetDDE_share
- http://technet2.microsoft.com/windowsserver/en/library/2c82586e-bd58-42b7-9976-228a23721e351033.mspx
- http://support.microsoft.com/kb/278259
- http://support.microsoft.com/kb/243330
Acknowledgements
This vulnerability was reported by Neutralbit with assistance from Digital Bond.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2007-6033 |
Severity Metric: | 0.57 |
Date Public: | 2007-11-19 |
Date First Published: | 2007-11-19 |
Date Last Updated: | 2008-02-26 00:34 UTC |
Document Revision: | 32 |