PT-2013-3935 · Schweitzer Engineering Laboratories · Sel-3505+2
Adam Crain
+1
·
Published
2013-08-09
·
Updated
2013-08-12
·
CVE-2013-2792
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Schweitzer Engineering Laboratories (SEL) SEL-2241, SEL-3505, and SEL-3530 RTAC master devices
Description
The issue allows remote attackers to cause a denial of service, resulting in an infinite loop, by sending a crafted DNP3 TCP packet.
Recommendations
For SEL-2241, SEL-3505, and SEL-3530 RTAC master devices, consider restricting access to DNP3 TCP packets until a fix is available.
As a temporary workaround, consider implementing network traffic filtering to block crafted DNP3 TCP packets.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sel-2241
Sel-3505
Sel-3530