CVE-2013-2794

UnknownEPSS 0.32%

Last modified

CVE-2013-2794 is a vulnerability of currently unknown severity. Triangle MicroWorks SCADA Data Gateway 2.50.0309 through 3.00.0616, DNP3 .NET Protocol components 3.06.0.171 through 3.15.0.369, and DNP3 C libraries 3.06.0000 through 3.15.0000 allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.

Description

Triangle MicroWorks SCADA Data Gateway 2.50.0309 through 3.00.0616, DNP3 .NET Protocol components 3.06.0.171 through 3.15.0.369, and DNP3 C libraries 3.06.0000 through 3.15.0000 allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line.

Metrics

EPSS Probability
0.32%

23.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
TrianglemicroworksAnsi C Source Code Libraries3.06.0000
TrianglemicroworksAnsi C Source Code Libraries3.07.0000
TrianglemicroworksAnsi C Source Code Libraries3.08.0000
TrianglemicroworksAnsi C Source Code Libraries3.09.0000
TrianglemicroworksAnsi C Source Code Libraries3.10.0000
TrianglemicroworksAnsi C Source Code Libraries3.11.0000
TrianglemicroworksAnsi C Source Code Libraries3.12.0000
TrianglemicroworksAnsi C Source Code Libraries3.13.0000
TrianglemicroworksAnsi C Source Code Libraries3.14.0000
TrianglemicroworksAnsi C Source Code Libraries3.15.0000
Trianglemicroworks.Net Communication Protocol Components3.06.0.171
Trianglemicroworks.Net Communication Protocol Components3.07.00
Trianglemicroworks.Net Communication Protocol Components3.08.00
Trianglemicroworks.Net Communication Protocol Components3.09.00
Trianglemicroworks.Net Communication Protocol Components3.10.00
Trianglemicroworks.Net Communication Protocol Components3.11.00
Trianglemicroworks.Net Communication Protocol Components3.14.00
Trianglemicroworks.Net Communication Protocol Components3.15.00
Trianglemicroworks.Net Communication Protocol Components3.15.0.369
TrianglemicroworksScada Data Gateway2.50
TrianglemicroworksScada Data Gateway2.50.0309
TrianglemicroworksScada Data Gateway2.51
TrianglemicroworksScada Data Gateway2.53
TrianglemicroworksScada Data Gateway2.54.0515
TrianglemicroworksScada Data Gateway2.54.0516
TrianglemicroworksScada Data Gateway2.54.0517
TrianglemicroworksScada Data Gateway2.54.0518
TrianglemicroworksScada Data Gateway2.54.0528
TrianglemicroworksScada Data Gateway2.54.0529
TrianglemicroworksScada Data Gateway2.54.0536
TrianglemicroworksScada Data Gateway2.54.0540
TrianglemicroworksScada Data Gateway2.54.0544
TrianglemicroworksScada Data Gateway2.54.0545
TrianglemicroworksScada Data Gateway2.54.0552
TrianglemicroworksScada Data Gateway2.54.0553
TrianglemicroworksScada Data Gateway2.54.0558
TrianglemicroworksScada Data Gateway2.54.0561
TrianglemicroworksScada Data Gateway2.54.0562
TrianglemicroworksScada Data Gateway2.54.0564
TrianglemicroworksScada Data Gateway2.54.0565
TrianglemicroworksScada Data Gateway2.54.0566
TrianglemicroworksScada Data Gateway2.54.0567
TrianglemicroworksScada Data Gateway2.54.0569
TrianglemicroworksScada Data Gateway2.54.0570
TrianglemicroworksScada Data Gateway2.54.0571
TrianglemicroworksScada Data Gateway2.54.0572
TrianglemicroworksScada Data Gateway2.54.0573
TrianglemicroworksScada Data Gateway2.54.0574
TrianglemicroworksScada Data Gateway2.54.0575
TrianglemicroworksScada Data Gateway2.54.0576

Showing 50 of 73 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-2794?
Triangle MicroWorks SCADA Data Gateway 2.50.0309 through 3.00.0616, DNP3 .NET Protocol components 3.06.0.171 through 3.15.0.369, and DNP3 C libraries 3.06.0000 through 3.15.0000 allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line.
How severe is CVE-2013-2794?
Severity scoring for CVE-2013-2794 is pending analysis. The EPSS model estimates a 0.32% probability of exploitation in the next 30 days.
How do I fix CVE-2013-2794?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-2794?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST