CVE-2013-2796
Summary
| CVE | CVE-2013-2796 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-08-09 23:55:00 UTC |
| Updated | 2013-08-12 20:21:00 UTC |
| Description | Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Schneider-electric | Citectscada | 7.10 | All | All | All |
| Application | Schneider-electric | Citectscada | 7.10 | All | All | All |
| Application | Schneider-electric | Citectscada | All | All | All | All |
| Application | Schneider-electric | Powerlogic Scada | 7.10 | All | All | All |
| Application | Schneider-electric | Powerlogic Scada | 7.10 | All | All | All |
| Application | Schneider-electric | Powerlogic Scada | All | All | All | All |
| Application | Schneider-electric | Vijeo Citect | 7.10 | All | All | All |
| Application | Schneider-electric | Vijeo Citect | 7.10 | All | All | All |
| Application | Schneider-electric | Vijeo Citect | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Schneider Electric Vijeo Citect, CitectSCADA, PowerLogic SCADA Vulnerability | ICS-CERT | MISC | ics-cert.us-cert.gov | US Government Resource |
| AVEVA Global Customer Support - Login | CONFIRM | www.citect.schneider-electric.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.