Triangle MicroWorks SCADA Data Gateway TLS/DTLS Information Leakage Vulnerability
Release date:
Updated on:
Affected Systems:
Trianglemicroworks SCADA Data Gateway <3.03.729
Description:
--------------------------------------------------------------------------------
SCADA Data Gateway is a Windows Application for system integrators and public utilities. It can collect OPC, IEC 60870-6 (TASE.2/ICCP), IEC 61850, IEC 60870-5, DNP3, the data on the Modbus Server/Slave Device is then transmitted to the Client supporting OPC, IEC 60870-6 (TASE.2/ICCP), IEC 60870-5, DNP3, other Control Systems of Modbus Client/Master communication protocols.
SCADA Data Gateway is bound with an OpenSSL (CVE-2014-0160) vulnerability with heartbleed vulnerability. Malicious users can exploit this vulnerability to obtain sensitive information.
<* Source: vendor
Link: http://secunia.com/advisories/58859/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Trianglemicroworks
------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.trianglemicroworks.com/products/scada-data-gateway/what%27s-new
This article permanently updates the link address: