PT-2013-2530 · Invensys · Invensys Wonderware Information Server
Denis Baranov
+6
·
Published
2013-05-09
·
Updated
2013-05-09
·
CVE-2013-0685
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Invensys Wonderware Information Server (WIS) versions 4.0 SP1 through 5.0
Description
The issue allows remote attackers to execute arbitrary code or cause a denial of service due to unrestricted size and amount values.
Recommendations
For versions 4.0 SP1 through 5.0, restrict size and amount values to prevent remote attackers from executing arbitrary code or causing a denial of service.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invensys Wonderware Information Server