CVE-2012-3005: Invensys Foxboro Control Software
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and Wonderware Historian, allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected products
- Invensys Foxboro Control Software: version 3.1 only; version 4.0 only
- Invensys Infusion Ce/fe/scada: up to and including 2.5
- Invensys Intouch: up to and including 2012
- Invensys Intouch/wonderware Application Server: up to and including 2012; version 10.0 only; version 10.5 only
- Invensys Wonderware Historian: up to and including 10.0; version 10.0 only
- Invensys Wonderware Inbatch: up to and including 9.5
- Invensys Wonderware Information Server: up to and including 4.5; version 3.1 only; version 4.0 only
Published 2012-07-26. Last modified 2026-06-16.