📦

suitelink

Vendor: wonderware

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 1 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 3.15% Exploit Prob.
Latest CVE CVE-2021-32999 Sep 23

Security Vulnerability Index

Page 1 / 1
7.5 CVSS

Improper handling of exceptional conditions in SuiteLink server while processing command 0x01

EPSS: 0.96%
7.5 CVSS

Null pointer dereference in SuiteLink server while processing command 0x0b

EPSS: 0.96%
7.5 CVSS

Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a

EPSS: 0.96%
7.5 CVSS

Null pointer dereference in SuiteLink server while processing command 0x07

EPSS: 0.96%
7.5 CVSS

Null pointer dereference in SuiteLink server while processing commands 0x03/0x10

EPSS: 0.96%
8.1 CVSS

Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06

EPSS: 0.94%
5.0 CVSS
CVE-2008-2005
Exploit Found

The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown) and possibly execute arbitrary code via a large length value in a Registration packet to TCP port 5413, which causes a memory allocation failure.

EPSS: 16.32%