First published: Tue May 06 2008(Updated: )
The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown) and possibly execute arbitrary code via a large length value in a Registration packet to TCP port 5413, which causes a memory allocation failure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wonderware InTouch | =8.0 | |
Wonderware SuiteLink | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2005 is classified as a moderate severity vulnerability due to its potential for denial of service and arbitrary code execution.
To fix CVE-2008-2005, update to WonderWare SuiteLink 2.0 Patch 01 or a later version.
CVE-2008-2005 affects WonderWare InTouch 8.0 and WonderWare SuiteLink 2.0 prior to Patch 01.
CVE-2008-2005 enables remote attackers to perform a denial of service attack through a NULL pointer dereference.
Yes, CVE-2008-2005 can be exploited by remote attackers by sending a specially crafted request.