Wonderware develops a focused line of industrial automation and supervisory control software, primarily through products such as InTouch and SuiteLink that are embedded in manufacturing and process-control environments. The observed vulnerability pattern centers on information-disclosure and access-control weaknesses, reflecting the sensitivity of credentials and configuration data in operational-technology systems where unauthorized access poses direct safety and continuity risks. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wonderware over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2005MEDIUM The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL po | May 6, 2008 | 5.0 | 36 | NO | YES |
CVE-2007-6033HIGH Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers, and possibly anonymous users, | Nov 20, 2007 | 8.8 | 24 | NO | NO |
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, whic | Aug 1, 2015 | 1.7 | 10 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wonderware.
Media articles that mention a CVE ID that affects a product developed by Wonderware — matched by CVE ID, not by vendor name.