PT-2020-12243 · Triangle Microworks · Triangle Microworks Scada Data Gateway

Chris Anastasio

+1

·

Published

2020-04-15

·

Updated

2020-04-22

·

CVE-2020-10615

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Triangle MicroWorks SCADA Data Gateway versions 2.41.0213 through 4.0.122 Triangle MicroWorks SCADA Data Gateway versions 3.02.0697 through 4.0.122
Description The issue allows remote attackers to cause a denial-of-service condition due to a lack of proper validation of the length of user-supplied data, prior to copying it to a fixed-length stack-based buffer. Authentication is not required to exploit this issue. It is related to a stack-based buffer overflow remote code execution vulnerability in the DNP3 GET FILE INFO function.
Recommendations For Triangle MicroWorks SCADA Data Gateway versions 2.41.0213 through 4.0.122, consider restricting access to the DNP3 protocol to minimize the risk of exploitation until a patch is available. For Triangle MicroWorks SCADA Data Gateway versions 3.02.0697 through 4.0.122, consider implementing additional validation for user-supplied data length to prevent buffer overflows. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10615
ZDI-20-547

Affected Products

Triangle Microworks Scada Data Gateway