CVE-2013-0685: Critical severity wonderware information server vulnerability
Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values, which allows remote attackers to execute arbitrary code or cause a denial of service (resource consumption) via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0685?
CVE-2013-0685 is considered a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2013-0685?
To fix CVE-2013-0685, update the Invensys Wonderware Information Server to a patched version that resolves this vulnerability.
What versions of Invensys Wonderware Information Server are affected by CVE-2013-0685?
CVE-2013-0685 affects versions 4.0 SP1SP1, 4.5 Portal, and 5.0 Portal of Invensys Wonderware Information Server.
Can CVE-2013-0685 lead to denial of service?
Yes, CVE-2013-0685 can potentially lead to a denial of service due to resource consumption by arbitrary code execution.
Is there a known exploitation method for CVE-2013-0685?
CVE-2013-0685 does not specify the exploitation vectors, making it a concern for various unknown methods of attack.