CVE-2012-0257: Invensys Archestra Application Object Toolkit
Medium severity, CVSS 6.8. EPSS: 3.2% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit 3.2 and earlier, and InTouch 10.0 through 10.5 might allow remote attackers to execute arbitrary code via a long string to the Open member, leading to a function-pointer overwrite.
Affected products
- Invensys Archestra Application Object Toolkit: up to and including 3.2
- Invensys Foxboro Control Software: up to and including 3.1
- Invensys Infusion Control Edition: up to and including 2.5
- Invensys Infusion Foundation Edition: up to and including 2.5
- Invensys Infusion Scada: up to and including 2.5
- Invensys Intouch: version 10.0 only; version 10.5 only
- Invensys Wonderware Application Server: up to and including 2012
- Invensys Wonderware Information Server: up to and including 4.5; version 3.1 only; version 4.0 only
Published 2012-04-02. Last modified 2026-06-16.