ZDI-23-1036: Triangle MicroWorks SCADA Data Gateway DbasSectorFileToExecuteOnReset Exposed Dangerous Function Remote Code Execution Vulnerability
Published Aug 4, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Triangle MicroWorks SCADA Data Gateway
Event History
Aug 4, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Mar 26, 2025
Advisory Published
via ZDI·05:07 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-1036?
The severity of ZDI-23-1036 is high due to the potential for remote attackers to execute arbitrary code.
2
How do I fix ZDI-23-1036?
To fix ZDI-23-1036, ensure that you apply the latest security patches or updates provided by Triangle MicroWorks for the SCADA Data Gateway.
3
What are the affected installations for ZDI-23-1036?
ZDI-23-1036 affects installations of Triangle MicroWorks SCADA Data Gateway that are not patched.
4
Is authentication required to exploit ZDI-23-1036?
Yes, authentication is required to exploit the vulnerability described in ZDI-23-1036.
5
What types of attacks can occur due to ZDI-23-1036?
Due to ZDI-23-1036, remote attackers can execute arbitrary code on the affected SCADA Data Gateway installations.