← Back

Wonderware

wonderware

3 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Intouch
intouch
Suitelink
suitelink

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Indusoft
Wonderware
2Intouch
Web Studio
May 6, 2026
Aug 1, 2015
N/A· v4
N/A· v3
1.7 LOW· v2
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive...Show more
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file.Show less
1Wonderware
2Intouch
Suitelink
Apr 23, 2026
May 6, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown)...Show more
The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown) and possibly execute arbitrary code via a large length value in a Registration packet to TCP port 5413, which causes a memory allocation failure.Show less
1Wonderware
1Intouch
Apr 23, 2026
Nov 20, 2007
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers, and possibly anonymous users, to execute arbitrary programs.