PT-2013-3931 · Schneider Electric · Substation Server

Adam Crain

+1

·

Published

2013-09-17

·

Updated

2013-09-18

·

CVE-2013-2788

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions SubSTATION Server versions 2.7.0033 through 2.8.0106
Description The issue concerns the DNP3 Slave service, which allows remote attackers to cause a denial of service. This can be achieved through unspecified vectors, resulting in an unhandled exception and process crash.
Recommendations For versions 2.7.0033 through 2.8.0106, consider disabling the DNP3 Slave service as a temporary workaround until a patch is available. Restrict access to the service to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2788

Affected Products

Substation Server