Vulnerability Description
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow remote attackers to cause a denial of service (driver crash and process restart) via a crafted DNP3 TCP packet.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novatech | Orion5 Dnp Master | 1.27.38 |
| Novatech | Orion5 Dnp Slave | 1.23.10 |
| Novatech | Orion5R Dnp Master | 1.27.38 |
| Novatech | Orion5R Dnp Slave | 1.23.10 |
| Novatech | Orionlx Dnp Master | 1.27.38 |
| Novatech | Orionlx Dnp Slave | 1.23.10 |
Related Weaknesses (CWE)
References
- http://ics-cert.us-cert.gov/advisories/ICSA-13-352-01US Government Resource
- http://ics-cert.us-cert.gov/advisories/ICSA-13-352-01US Government Resource
FAQ
What is CVE-2013-2821?
CVE-2013-2821 is a vulnerability with a CVSS score of 7.1 (HIGH). NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow remote attacker...
How severe is CVE-2013-2821?
CVE-2013-2821 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-2821?
Check the references section above for vendor advisories and patch information. Affected products include: Novatech Orion5 Dnp Master, Novatech Orion5 Dnp Slave, Novatech Orion5R Dnp Master, Novatech Orion5R Dnp Slave, Novatech Orionlx Dnp Master.