IWS Remote Agent Module Design Weakness

January 5, 2012

InduSoft Web Studio (IWS) is a collection of automation tools that provide all the automation building blocks to develop HMIs (Human-Machine Interface), SCADA (Supervisory Control and Data Acquisition) systems and embedded instrumentation solutions. Typically a InduSoft Web Studio project is running on a embedded Windows device, which connects to machines, processors or other data-acquisition equipments. The embedded Windows device can connect to a Remote Agent component, which supports various message types in order to handle different tasks.

A design flaw exists in the Remote Agent component of InduSoft Web Studio. Specifically, the vulnerability is due to a lack of authentication when handling client requests. A remote attacker can exploit this vulnerability by sending a crafted message to the Remote Agent component. Successful exploitation can result in arbitrary file creation or code execution in the security context of the Remote Agent process.

The vulnerability has been assigned as CVE-2011-4051.

SonicWALL has released an IPS signature to detect and block specific exploitation attempts targeting this vulnerability. The signature is listed below:

  • 7265 InduSoft Web Studio Remote Code Execution