← Back to home
ICSA-13-067-02  ·  Published 2025-06-06  ·  View on CISA ICS-CERT ↗

Invensys Wonderware Win-XML Exporter Improper Input Validation Vulnerability

CVSS 9.3 CRITICAL

CVEs (1)

Remediations

  • Invensys has developed an update to the Win-XML Exporter that mitigates this vulnerability. The Positive Technologies Research Team has tested the update and validated that it fixes the vulnerability. Instructions and a link to the update are found on the Invensys download page.
  • According to Invensys, any machine running one or more of the products listed above is affected and should be patched. No other components of the Wonderware installed products are affected. Users should install the update using instructions provided in the ReadMe file for the product and component being installed. Invensys recommends that users: Read the installation instructions provided with the patch. Shut down any of the affected software products. Install the update. Restart the software.

Affected Vendors

Invensys

Affected Products (1)

Invensys · Win-XML Exporter <=1522.148.0.0

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more