Wonderware SuiteLink 'slssvc.exe' Remote Denial of Service Vulnerability
BID:28974
Info
Wonderware SuiteLink 'slssvc.exe' Remote Denial of Service Vulnerability
| Bugtraq ID: | 28974 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-2005 |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2008 12:00AM |
| Updated: | Sep 17 2008 06:10PM |
| Credit: | Sebastian Muniz from Core Security Technologies |
| Vulnerable: |
Wonderware SuiteLink 2.0 |
| Not Vulnerable: |
Wonderware SuiteLink 2.0 patch 01 |
Discussion
Wonderware SuiteLink 'slssvc.exe' Remote Denial of Service Vulnerability
Wonderware SuiteLink is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Given the nature of this issue, the attacker may also be able to execute arbitrary code, but this has not been confirmed.
Versions prior to Wonderware SuiteLink 2.0 Patch 01 are vulnerable.
UPDATE: References to Wonderware InTouch 8.0 have been removed; that software is not affected by this vulnerability.
Wonderware SuiteLink is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Given the nature of this issue, the attacker may also be able to execute arbitrary code, but this has not been confirmed.
Versions prior to Wonderware SuiteLink 2.0 Patch 01 are vulnerable.
UPDATE: References to Wonderware InTouch 8.0 have been removed; that software is not affected by this vulnerability.
Exploit / POC
Solution / Fix
Wonderware SuiteLink 'slssvc.exe' Remote Denial of Service Vulnerability
Solution:
The vendor has released fixes. Please contact the vendor for information on how to obtain and apply updates.
Solution:
The vendor has released fixes. Please contact the vendor for information on how to obtain and apply updates.
References
Wonderware SuiteLink 'slssvc.exe' Remote Denial of Service Vulnerability
References:
References:
- Vendor Homepage (Wonderware)
- CORE-2008-0129 - Wonderware SuiteLink Denial of Service vulnerability (CORE Security Technologies Advisories
) - Vulnerability Note VU#596268 (US-CERT)