PT-2020-12239 · Triangle Microworks · Scada Data Gateway
Ali Abbasi
+2
·
Published
2020-04-15
·
Updated
2020-04-22
·
CVE-2020-10611
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Triangle MicroWorks SCADA Data Gateway versions 2.41.0213 through 4.0.122
Triangle MicroWorks SCADA Data Gateway versions 3.02.0697 through 4.0.122
Description
The issue allows remote attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, resulting in a type confusion condition. Authentication is not required to exploit this issue. This is only applicable to installations using DNP3 Data Sets.
Recommendations
For versions 2.41.0213 through 4.0.122, consider restricting access to the DNP3 Data Sets until a patch is available.
For versions 3.02.0697 through 4.0.122, consider implementing additional validation for user-supplied data to prevent type confusion conditions.
At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scada Data Gateway