SCADA Data Gateway Serial-Connected Devices Local Denial of Service Vulnerability
BID:67723
Info
SCADA Data Gateway Serial-Connected Devices Local Denial of Service Vulnerability
| Bugtraq ID: | 67723 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2343 |
| Remote: | No |
| Local: | Yes |
| Published: | May 29 2014 12:00AM |
| Updated: | May 29 2014 12:00AM |
| Credit: | Adam Crain and Chris Sistrunk |
| Vulnerable: |
Triangle MicroWorks SCADA Data Gateway 3.0.616 |
| Not Vulnerable: |
Triangle MicroWorks SCADA Data Gateway 3.0.635 |
Discussion
SCADA Data Gateway Serial-Connected Devices Local Denial of Service Vulnerability
SCADA Data Gateway is prone to a local denial-of-service vulnerability because the application fails to properly validate the user-supplied input.
An attacker can leverage this issue to consume resources resulting in denial-of-service condition; denying service to legitimate users.
Note: To exploit this issue local access to the serial-based outstation is required.
Versions prior to SCADA Data Gateway 3.00.0635 are vulnerable.
SCADA Data Gateway is prone to a local denial-of-service vulnerability because the application fails to properly validate the user-supplied input.
An attacker can leverage this issue to consume resources resulting in denial-of-service condition; denying service to legitimate users.
Note: To exploit this issue local access to the serial-based outstation is required.
Versions prior to SCADA Data Gateway 3.00.0635 are vulnerable.
Exploit / POC
SCADA Data Gateway Serial-Connected Devices Local Denial of Service Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SCADA Data Gateway Serial-Connected Devices Local Denial of Service Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
SCADA Data Gateway Serial-Connected Devices Local Denial of Service Vulnerability
References:
References:
- Triangle MicroWorks Homepage (Triangle MicroWorks)
- Triangle MicroWorks, Inc. DNP3 Master Source Code Library (Triangle MicroWorks)
- Advisory (ICSA-14-149-01) Triangle MicroWorks Uncontrolled Resource Consumption (CERT)