← Back to home
ICSA-12-171-01  ·  Published 2025-06-05  ·  View on CISA ICS-CERT ↗

Wonderware SuiteLink Unallocated Unicode String Vulnerability

CVSS 5.0 MEDIUM

CVEs (1)

Remediations

  • Invensys recommends the following mitigations: Apply security update patch to affected nodes. Upgrade to InTouch/Wonderware Application Server (IT 10.5, WAS 3.5) or later. Upgrade to DASABCIP 4.1 SP2 or DASSiDirect 3.0. Install DAServer Runtime Components Upgrade 3.0 SP2, 3.0 SP3 or higher for any DAServer, DI Object, or third-party DAServer installation. The Invensys security update patch can be found at the Wonderware download Web site.

Affected Vendors

Invensys

Affected Products (1)

Invensys · Wonderware slssvc service <=54.x.x.x

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more