Vulnerability Description
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Catapultsoftware | Catapult Dnp3 I\/O Driver | <= 7.20.56 |
| Ge | Intelligent Platforms Proficy Dnp3 I\/O Driver | <= 7.20 |
| Ge | Intelligent Platforms Proficy Hmi\/Scada Cimplicity | 4.01 |
| Ge | Intelligent Platforms Proficy Hmi\/Scada Ifix | 5.0 |
Related Weaknesses (CWE)
References
- http://ics-cert.us-cert.gov/advisories/ICSA-13-297-01US Government Resource
- http://ics-cert.us-cert.gov/advisories/ICSA-13-297-02US Government Resource
- http://support.ge-ip.com/support/index?page=kbchannel&id=S:KB15805Vendor Advisory
- http://support.ge-ip.com/support/resources/sites/GE_FANUC_SUPPORT/content/live/KVendor Advisory
- http://ics-cert.us-cert.gov/advisories/ICSA-13-297-01US Government Resource
- http://ics-cert.us-cert.gov/advisories/ICSA-13-297-02US Government Resource
- http://support.ge-ip.com/support/index?page=kbchannel&id=S:KB15805Vendor Advisory
- http://support.ge-ip.com/support/resources/sites/GE_FANUC_SUPPORT/content/live/KVendor Advisory
FAQ
What is CVE-2013-2823?
CVE-2013-2823 is a vulnerability with a CVSS score of 4.7 (MEDIUM). The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent ...
How severe is CVE-2013-2823?
CVE-2013-2823 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-2823?
Check the references section above for vendor advisories and patch information. Affected products include: Catapultsoftware Catapult Dnp3 I\/O Driver, Ge Intelligent Platforms Proficy Dnp3 I\/O Driver, Ge Intelligent Platforms Proficy Hmi\/Scada Cimplicity, Ge Intelligent Platforms Proficy Hmi\/Scada Ifix.