Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-2005

EPSS 47.20% · P98
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-2005

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown) and possibly execute arbitrary code via a large length value in a Registration packet to TCP port 5413, which causes a memory allocation failure.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
WonderWare SuiteLink slssvc.exe远程拒绝服务漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WonderWare是一家工业自动化和信息软件解决方案的供应商。 WonderWare在处理畸形请求数据时存在漏洞,远程攻击者可能利用此漏洞导致服务不可用。 WonderWare的SuiteLink服务在5413/TCP端口上监听连接。连接到该服务的非认证客户端程序可以发送畸形报文,通过调用new()运算符导致内存分配操作失败并返回空指针。由于对内存分配操作的结果缺少错误检查,程序之后可能会使用空指针作为内存拷贝操作的目标,这可能触发内存访问异常并终止服务。 攻击者可以通过在Registration报文中
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-2005

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-2005

登录查看更多情报信息。

Same Patch Batch · n/a · 2008-05-06 · 11 CVEs total

CVE-2008-2091KubeLabs Kubelance 'ipn.php' 本地文件包含漏洞
CVE-2008-2092Linksys SPA-2102 Phone Adapter Packet Handling 拒绝服务漏洞
CVE-2008-2093Joomla! and Mambo Community Builder 'com_profiler' Component 'index.php' SQL注入漏洞
CVE-2008-2094XOOPS Article Module 'article.php' SQL注入漏洞
CVE-2008-2095Joomla! FlippingBook Component 'book_id' 参数SQL注入漏洞
CVE-2008-2080NASA CDF库src/lib/cdfread64.c文件栈溢出漏洞
CVE-2008-2087Softbiz Web Host Directory Script 'search_result.php' SQL注入漏洞
CVE-2008-2088PHP Forge 'id' Parameter SQL注入漏洞
CVE-2008-2089Sun Solaris 10 未明SCTP协议处理远程拒绝服务漏洞
CVE-2008-2090Sun Solaris SCTP Network Flooding 远程拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2008-2005

No comments yet


Leave a comment