First published: Thu Aug 22 2013(Updated: )
The Kepware DNP Master Driver for the KEPServerEX Communications Platform before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via crafted DNP3 packets to TCP port 20000 and allows physically proximate attackers to cause a denial of service (master-station infinite loop) via crafted input over a serial line.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
PTC KEPServerEX | <5.12.140.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2789 is considered a high severity vulnerability due to its potential to cause a denial of service.
To mitigate CVE-2013-2789, upgrade to KEPServerEX version 5.12.140.0 or later.
CVE-2013-2789 can be exploited by remote attackers and also by physically proximate attackers.
CVE-2013-2789 is exploited through crafted DNP3 packets sent to TCP port 20000.
The impact of CVE-2013-2789 is a denial of service that causes an infinite loop in the DNP Master Driver.