PT-2013-2530 · Invensys · Invensys Wonderware Information Server

Denis Baranov

+6

·

Published

2013-05-09

·

Updated

2013-05-09

·

CVE-2013-0685

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Invensys Wonderware Information Server (WIS) versions 4.0 SP1 through 5.0
Description The issue allows remote attackers to execute arbitrary code or cause a denial of service due to unrestricted size and amount values.
Recommendations For versions 4.0 SP1 through 5.0, restrict size and amount values to prevent remote attackers from executing arbitrary code or causing a denial of service.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0685

Affected Products

Invensys Wonderware Information Server