CVE-2008-2005: Null Pointer Dereference
The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown) and possibly execute arbitrary code via a large length value in a Registration packet to TCP port 5413, which causes a memory allocation failure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2005?
CVE-2008-2005 is classified as a moderate severity vulnerability due to its potential for denial of service and arbitrary code execution.
How do I fix CVE-2008-2005?
To fix CVE-2008-2005, update to WonderWare SuiteLink 2.0 Patch 01 or a later version.
What systems are affected by CVE-2008-2005?
CVE-2008-2005 affects WonderWare InTouch 8.0 and WonderWare SuiteLink 2.0 prior to Patch 01.
What type of attack does CVE-2008-2005 enable?
CVE-2008-2005 enables remote attackers to perform a denial of service attack through a NULL pointer dereference.
Can CVE-2008-2005 be exploited remotely?
Yes, CVE-2008-2005 can be exploited by remote attackers by sending a specially crafted request.