CVE-2013-2823: Input Validation
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2823?
CVE-2013-2823 has been classified with a high severity rating due to its potential to allow physical proximity attackers to manipulate the system.
How do I fix CVE-2013-2823?
To fix CVE-2013-2823, upgrade to version 7.2.0.60 or later for the Catapult DNP3 I/O driver, or version 7.20k or later for the GE Intelligent Platforms Proficy DNP3 I/O driver.
What types of systems are affected by CVE-2013-2823?
CVE-2013-2823 affects the Catapult DNP3 I/O driver and various versions of the GE Intelligent Platforms Proficy DNP3 I/O driver utilized in HMI/SCADA systems.
What are the potential impacts of CVE-2013-2823?
The potential impacts of CVE-2013-2823 include unauthorized access and modifications to system operations by attackers in close proximity.
Who is responsible for addressing CVE-2013-2823?
Organizations using the affected versions of the drivers are responsible for addressing CVE-2013-2823 by applying the appropriate updates to mitigate the vulnerability.