PT-2020-12241 · Triangle Microworks · Scada Data Gateway

Ali Abbasi

+2

·

Published

2020-04-15

·

Updated

2020-04-22

·

CVE-2020-10613

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Triangle MicroWorks SCADA Data Gateway versions 2.41.0213 through 4.0.122 Triangle MicroWorks SCADA Data Gateway versions 3.02.0697 through 4.0.122
Description The issue allows remote attackers to disclose sensitive information due to the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. Authentication is not required to exploit this issue. This is only applicable to installations using DNP3 Data Sets.
Recommendations For versions 2.41.0213 through 4.0.122, consider restricting access to the DNP3 Data Sets until a patch is available. For versions 3.02.0697 through 4.0.122, consider implementing additional validation for user-supplied data to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10613
ZDI-20-548

Affected Products

Scada Data Gateway