CVE

CVE-2008-2005

Severity:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
06/05/2008
Last modified:
11/10/2018

Description

The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown) and possibly execute arbitrary code via a large length value in a Registration packet to TCP port 5413, which causes a memory allocation failure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wonderware:intouch:8.0:*:*:*:*:*:*:*
cpe:2.3:a:wonderware:suitelink:2.0:*:*:*:*:*:*:*