CVE-2012-3007: Buffer Overflow
Stack-based buffer overflow in slssvc.exe before 58.x in Invensys Wonderware SuiteLink in the Invensys System Platform software suite, as used in InTouch/Wonderware Application Server IT before 10.5 and WAS before 3.5, DASABCIP before 4.1 SP2, DASSiDirect before 3.0, DAServer Runtime Components before 3.0 SP2, and other products, allows remote attackers to cause a denial of service (daemon crash or hang) via a long Unicode string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3007?
CVE-2012-3007 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2012-3007?
To fix CVE-2012-3007, you should update to the latest version of Invensys Wonderware SuiteLink or apply any available patches.
Which versions of Invensys software are affected by CVE-2012-3007?
CVE-2012-3007 affects versions of Invensys Wonderware SuiteLink before 58.x, including specific versions of InTouch/Wonderware Application Server and DASABCIP.
What type of vulnerability is CVE-2012-3007?
CVE-2012-3007 is a stack-based buffer overflow vulnerability that can lead to potential system compromise.
What is the impact of exploiting CVE-2012-3007?
Exploiting CVE-2012-3007 could allow an attacker to execute arbitrary code on the affected systems.