CVE-2013-2818: Input Validation
Published Dec 1, 2013
·Updated
The DNP Master Driver in Alstom e-terracontrol 3.5, 3.6, and 3.7 allows physically proximate attackers to cause a denial of service (infinite loop and DNP3 service disruption) via crafted input over a serial line.
Affected Software
3 affected components
Alstom e-terracontrol=3.5
Alstom e-terracontrol=3.6
Alstom e-terracontrol=3.7
Event History
Dec 1, 2013
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2818?
CVE-2013-2818 has a critical severity rating as it can lead to a denial of service.
2
How do I fix CVE-2013-2818?
To fix CVE-2013-2818, update Alstom e-terracontrol to the latest version that addresses this vulnerability.
3
What are the affected versions of the Alstom e-terracontrol software for CVE-2013-2818?
The affected versions for CVE-2013-2818 are 3.5, 3.6, and 3.7 of Alstom e-terracontrol.
4
What type of attack does CVE-2013-2818 enable?
CVE-2013-2818 enables physically proximate attackers to execute a denial of service attack.
5
What impact does CVE-2013-2818 have on the DNP Master Driver?
CVE-2013-2818 causes the DNP Master Driver to enter an infinite loop, disrupting DNP3 services.