Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

ADVISORIES

Wonderware SuiteLink's Denial of Reported Service Vulnerability

- The report was issued on Monday in a CoreLabs Advisory

By: Traian Teglet, Technology News Editor

Security researchers at Core Security Technologies have issued a warning statement on Monday according to which they found a rare vulnerability in Wonderware subsidiary's InTouch SuiteLink application. Wonderware, a business unit of Invensys, is a software manufacturer that offers solutions to business users in areas such as Production and Performance Management, Geographical SCADA and Supervisory HMI (Human-Machine Interface).

Core Security found the vulnerability in Wonderware SuiteLink Service and it is said that the flaw allows the interference of an unauthenticated remote control that could shutdown the service. This means that a hacker could breach the SCADA (Supervisory Control And Data Acquisition) application by connecting to a SuiteLink service TCP port. The vulnerability hasn't been proven to allow remote code execution but according to Core Security, a potential scenario hasn't been excluded.

According to the Security company, systems running WonderWare SuiteLink prior to version 2.0 Patch 01 are susceptible to the reported bug. While testing a system running WonderWare InTouch 8, Sebastian Muniz from the Exploit Writers Team, has discovered the above mentioned vulnerability. According to the American National Institute of Standards and Technology (NIST), the bug has been reported as being a high-risk one. Wonderware has made available to its registered customers a technical document addressing this issue.

With consumer and business software applications this sort of breaches are somewhat common. Bugs involving SCADA applications aren't that frequent, but they can cause a lot of damage. There are a number of security companies that try to develop protective software applications for SCADA systems.

According to Wonderware's website "one third of the world's plants run Wonderware software solutions.". A hacking attack that could make use of the discovered vulnerability will most certainly cause some serious damage on a worldwide scale. Wonderware customers still running systems using SuiteLink 2.0 Patch 01 should contact the company website for more information.


MORE RELATED ARTICLES: Adobe Acrobat Reader and Professional Vulnerability Reported BitDefender Antivirus 2008 Needs Updates Malicious Behavior Threat Searching for Windows Stations Ubuntu Weekly Report: 13th - 19th April, 2008 Norton Antivirus and Norton 360 Vulnerable - Patch Inside!
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:


8th May 2008, 13:07 GMT | Copyright (c) 2008 Softpedia | Contact:
Read by 187 user(s) | Rating: | 1 vote(s) so far | Cast your vote:
Wonderware SuiteLink's Denial of Reported Service Vulnerability - USER OPINIONS




We are sorry, there are no opinions available for this article.






SHARE YOUR OPINION ABOUT Wonderware SuiteLink's Denial of Reported Service Vulnerability

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive