CVE-2012-4710: Invensys Wonderware Win-XML Exporter

High severity, CVSS 9.3. EPSS: 2.1% chance of exploitation in the next 30 days.

Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference.

Affected products

  • Invensys Wonderware Win-XML Exporter: version 1522.148.0.0 only

Published 2013-04-04. Last modified 2026-06-16.