CG Automation ePAQ-9410 Substation Gateway Improper Input Validation
Summary
| CVE | CVE-2014-0762 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-28 01:55:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The CG Automation Software DNP3 driver, used in the ePAQ-9410 Substation Gateway products, does not validate input correctly. An attacker could cause the software to go into an infinite loop, causing the process to crash. The system must be restarted manually to clear the condition. |
Risk And Classification
Primary CVSS: v2.0 4.7 from [email protected]
AV:L/AC:M/Au:N/C:N/I:N/A:C
Problem Types: CWE-20 | CWE-20 CWE-20
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 4.7 | AV:L/AC:M/Au:N/C:N/I:N/A:C | |
| 2.0 | [email protected] | Secondary | 4.7 | AV:L/AC:M/Au:N/C:N/I:N/A:C | |
| 2.0 | CNA | CVSS | 4.7 | AV:L/AC:M/Au:N/C:N/I:N/A:C |
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:L/AC:M/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Qeiinc | Epaq-9410 Substation Gateway | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | CG Automation | EPAQ-9410 Substation Gateway | affected all versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/news-events/ics-advisories/icsa-14-238-01 | [email protected] | www.cisa.gov | |
| mail.cgautomationusa.com/login.aspx | [email protected] | mail.cgautomationusa.com | |
| CG Automation Improper Input Validation | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Adam Crain of Automatak (en)
CNA: Chris Sistrunk of Mandiant (en)
Additional Advisory Data
Solutions
CNA: CG Automation has fixed this vulnerability with updated software. Users may obtain the updated software by downloading from this web address: http://mail.cgautomationusa.com/login.aspx
There are currently no legacy QID mappings associated with this CVE.