PT-2013-3935 · Schweitzer Engineering Laboratories · Sel-3505+2

Adam Crain

+1

·

Published

2013-08-09

·

Updated

2013-08-12

·

CVE-2013-2792

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Schweitzer Engineering Laboratories (SEL) SEL-2241, SEL-3505, and SEL-3530 RTAC master devices
Description The issue allows remote attackers to cause a denial of service, resulting in an infinite loop, by sending a crafted DNP3 TCP packet.
Recommendations For SEL-2241, SEL-3505, and SEL-3530 RTAC master devices, consider restricting access to DNP3 TCP packets until a fix is available. As a temporary workaround, consider implementing network traffic filtering to block crafted DNP3 TCP packets. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2792

Affected Products

Sel-2241
Sel-3505
Sel-3530