PT-2015-3273 · Arbiter+1 · Arbiter 1094B Gps Substation Clock+2

Publicado

2015-01-17

·

Atualizado

2016-09-20

·

CVE-2014-9194

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Arbiter 1094B GPS Substation Clock (affected versions not specified) KW Multiprog and KW ProConOS (affected versions not specified)
Description The issue allows remote attackers to cause disruption or execute arbitrary commands. For the Arbiter 1094B GPS Substation Clock, this can be achieved via crafted radio transmissions that spoof GPS satellite broadcasts. In the case of KW Multiprog and KW ProConOS, the vulnerability is related to errors in managing registration data, which can be exploited using the PLC configuration protocol.
Recommendations For Arbiter 1094B GPS Substation Clock, consider implementing signal validation to prevent spoofed GPS transmissions until a patch is available. For KW Multiprog and KW ProConOS, restrict access to the configuration protocol to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Insufficient Verification of Data Authenticity

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-02182
CVE-2014-9194

Produtos afetados

Arbiter 1094B Gps Substation Clock
Kw Multiprog
Kw Proconos