PT-2014-4638 · Copa Data · Copa-Data Zenon Dnp3 Ng Driver+1

Published

2014-06-05

·

Updated

2014-06-05

·

CVE-2014-2345

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions COPA-DATA zenon DNP3 NG driver (DNP3 master) versions 7.10 through 7.11 SP0 build 10238 COPA-DATA zenon DNP3 Process Gateway (DNP3 outstation) versions 7.11 SP0 build 10238 and earlier
Description The issue allows remote attackers to cause a denial of service by sending a crafted DNP3 packet over TCP, resulting in an infinite loop and process crash.
Recommendations For COPA-DATA zenon DNP3 NG driver (DNP3 master) versions 7.10 through 7.11 SP0 build 10238, update to a version that includes a fix for this issue. For COPA-DATA zenon DNP3 Process Gateway (DNP3 outstation) versions 7.11 SP0 build 10238 and earlier, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to the DNP3 protocol to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2345

Affected Products

Copa-Data Zenon Dnp3 Ng Driver
Copa-Data Zenon Dnp3 Process Gateway