COPA-DATA zenon DNP3 Improper Input Validation
Summary
| CVE | CVE-2014-2345 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-06-05 17:55:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | COPA-DATA zenon DNP3 NG driver (DNP3 master) 7.10 and 7.11 through 7.11 SP0 build 10238 and zenon DNP3 Process Gateway (DNP3 outstation) 7.11 SP0 build 10238 and earlier allow remote attackers to cause a denial of service (infinite loop and process crash) by sending a crafted DNP3 packet over TCP. |
Risk And Classification
Primary CVSS: v2.0 7.1 from [email protected]
AV:N/AC:M/Au:N/C:N/I:N/A:C
Problem Types: CWE-20 | CWE-20 CWE-20
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 7.1 | AV:N/AC:M/Au:N/C:N/I:N/A:C | |
| 2.0 | [email protected] | Secondary | 7.1 | AV:N/AC:M/Au:N/C:N/I:N/A:C | |
| 2.0 | CNA | CVSS | 7.1 | AV:N/AC:M/Au:N/C:N/I:N/A:C |
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:M/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Copadata | Zenon Dnp3 Ng Driver | 7.10 | All | All | All |
| Application | Copadata | Zenon Dnp3 Ng Driver | 7.11 | - | All | All |
| Application | Copadata | Zenon Dnp3 Ng Driver | 7.11 | sp0_build_10238 | All | All |
| Application | Copadata | Zenon Dnp3 Process Gateway | 7.11 | sp0_build_10238 | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | COPA-DATA | Zenon DNP3 NG Driver DNP3 Master | affected 7.10 SP0 7.11 SP0 build 10238 custom | Not specified |
| CNA | COPA-DATA | Zenon DNP3 Process Gateway DNP3 Outstation | affected 7.11 SP0 build 10238 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/news-events/ics-advisories/icsa-14-154-01 | [email protected] | www.cisa.gov | |
| COPA-DATA Improper Input Validation | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| 404 | af854a3a-2127-422b-91ae-364da2661108 | www.copadata.com | |
| 404 | af854a3a-2127-422b-91ae-364da2661108 | www.copadata.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Automation software company Ing. Punzenberger COPA-DATA GmbH (en)
Additional Advisory Data
Solutions
CNA: Build 11206 for Version zenon 7.11 is available that contains updated versions of the affected products that resolve the discovered vulnerabilities. COPA-DATA recommends upgrading or updating the affected products to this version. Please see Knowledge Base articles 179444 and 178001 located here: http://www.copadata.com/en/support.html System integrators and asset owners should contact their local COPA-DATA representative for further information on how to obtain this update.
There are currently no legacy QID mappings associated with this CVE.