OleumTech WIO Family Improper Input Validation
Summary
| CVE | CVE-2014-2360 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-07-24 14:55:07 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules allow remote attackers to execute arbitrary code via packets that report a high battery voltage. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: CWE-20 | CWE-20 CWE-20
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P | |
| 2.0 | [email protected] | Secondary | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P | |
| 2.0 | CNA | CVSS | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P |
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Oleumtech | Sensor Wireless I/o Module | - | All | All | All |
| Hardware | Oleumtech | Wio Dh2 Wireless Gateway | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | OleumTech | WIO DH2 Wireless Gateway | affected All versions | Not specified |
| CNA | OleumTech | Sensor Wireless I/O Modules | affected All versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| OleumTech WIO DH2 Wireless Gateway CVE-2014-2360 Remote Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| OleumTech WIO Family Vulnerabilities | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| support.oleumtech.com | [email protected] | support.oleumtech.com | |
| www.cisa.gov/news-events/ics-advisories/icsa-14-202-01a | [email protected] | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Lucas Apa and Carlos Mario Penagos Hollman of IOActive (en)
Additional Advisory Data
Solutions
CNA: OleumTech has created updates for both BreeZ and the gateway to mitigate all these vulnerabilities. These updates allow users to encrypt their wireless traffic with AES256. To obtain these updates, please log in to the OleumTech download center ( http://support.oleumtech.com/ ) or contact OleumTech tech support:Phone: 866-508-8586 Email: [email protected]
There are currently no legacy QID mappings associated with this CVE.