CVE-2013-2811: Input Validation
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow remote attackers to cause a denial of service (infinite loop) via a crafted DNP3 TCP packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2811?
CVE-2013-2811 is classified as a high severity vulnerability due to its potential for remote denial of service attacks.
How do I fix CVE-2013-2811?
To mitigate CVE-2013-2811, users should upgrade the affected Catapult DNP3 I/O driver to version 7.2.0.60 or later and the GE Intelligent Platforms Proficy DNP3 I/O driver to version 7.20k or later.
Which products are affected by CVE-2013-2811?
CVE-2013-2811 affects the Catapult DNP3 I/O driver and GE Intelligent Platforms Proficy DNP3 I/O driver versions prior to specified updates.
What type of attack can CVE-2013-2811 enable?
CVE-2013-2811 can allow an attacker to execute a remote denial of service attack, potentially disrupting services.
Is there a known exploit for CVE-2013-2811?
Yes, there are known methods that remote attackers can use to exploit CVE-2013-2811, thus emphasizing the need for prompt updates.