Invensys Wonderware Information Server CVE-2013-0685 Denial of Service Vulnerability
BID:59709
Info
Invensys Wonderware Information Server CVE-2013-0685 Denial of Service Vulnerability
| Bugtraq ID: | 59709 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-0685 |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2013 12:00AM |
| Updated: | May 07 2013 12:00AM |
| Credit: | Timur Yunusov, Alexey Osipov, and Ilya Karpov of the Positive Technologies Research Team |
| Vulnerable: |
Invensys Wonderware Information Server 4.5 Portal Invensys Wonderware Information Server 4.0 SP1 |
| Not Vulnerable: | |
Discussion
Invensys Wonderware Information Server CVE-2013-0685 Denial of Service Vulnerability
Invensys Wonderware Information Server is prone to a denial-of-service vulnerability.
Successful exploits may allow an attacker to trigger high CPU consumption and make the application unresponsive. Note that this issue could be exploited to execute arbitrary code, however, Symantec has not been confirmed.
The following versions are vulnerable:
Wonderware Information Server 4.0 SP1
Wonderware Information Server 4.5 Portal
Wonderware Information Server 5.0 Portal
Invensys Wonderware Information Server is prone to a denial-of-service vulnerability.
Successful exploits may allow an attacker to trigger high CPU consumption and make the application unresponsive. Note that this issue could be exploited to execute arbitrary code, however, Symantec has not been confirmed.
The following versions are vulnerable:
Wonderware Information Server 4.0 SP1
Wonderware Information Server 4.5 Portal
Wonderware Information Server 5.0 Portal
Exploit / POC
Invensys Wonderware Information Server CVE-2013-0685 Denial of Service Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
Invensys Wonderware Information Server CVE-2013-0685 Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.