CVE-2013-2787: Input Validation
Published Oct 13, 2013
·Updated
Alstom e-terracontrol 3.5, 3.6, and 3.7 allows remote attackers to cause a denial of service (infinite loop) via crafted DNP3 packets.
Affected Software
3 affected components
Alstom e-terracontrol=3.5
Alstom e-terracontrol=3.6
Alstom e-terracontrol=3.7
Event History
Oct 13, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2787?
CVE-2013-2787 has a severity level that is categorized as high due to its potential to cause a denial of service.
2
How do I fix CVE-2013-2787?
To mitigate CVE-2013-2787, it is recommended to upgrade Alstom e-terracontrol to the latest available version that addresses this vulnerability.
3
What systems are affected by CVE-2013-2787?
CVE-2013-2787 affects Alstom e-terracontrol versions 3.5, 3.6, and 3.7.
4
What type of attack is possible with CVE-2013-2787?
CVE-2013-2787 allows remote attackers to execute a denial of service attack by sending crafted DNP3 packets.
5
When was CVE-2013-2787 disclosed?
CVE-2013-2787 was disclosed in 2013, specifically noted for its impact on industrial control systems.