Local DoS Vulnerability of SCADA Data Gateway Connection Devices

Source: Internet
Author: User

Release date:
Updated on: 2014-06-03

Affected Systems:
Trianglemicroworks SCADA Data Gateway <3.00.0635
Trianglemicroworks SCADA Data Gateway
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67723
CVE (CAN) ID: CVE-2014-2343
 
SCADA Data Gateway is a Windows Application for system integrators and public utilities. It can collect OPC, IEC 60870-6 (TASE.2/ICCP), IEC 61850, IEC 60870-5, DNP3, the data on the Modbus Server/Slave Device is then transmitted to the Client supporting OPC, IEC 60870-6 (TASE.2/ICCP), IEC 60870-5, DNP3, other Control Systems of Modbus Client/Master communication protocols.
 
Before SCADA Data Gateway 3.00.0635, a security vulnerability exists when processing DNP requests specially crafted on a serial line. Attackers with close physical locations can cause denial of service (excessive Data processing ).
 
<* Source: Adam Crain
Chris Sistrunk
*>

Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
 
Trianglemicroworks
------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
 
Http://www.trianglemicroworks.com/products/scada-data-gateway
Http://www.trianglemicroworks.com/products/scada-data-gateway/what%27s-new
Reference: http://ics-cert.us-cert.gov/advisories/ICSA-14-149-01

This article permanently updates the link address:

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.