SB2014053101 - Multiple vulnerabilities in SCADA Data Gateway
Published: May 31, 2014 Updated: August 10, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2014-2342)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows remote attackers to cause a denial of service (excessive data processing) via a crafted DNP3 packet.
2) Input validation error (CVE-ID: CVE-2014-2343)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows physically proximate attackers to cause a denial of service (excessive data processing) via a crafted DNP request over a serial line.
Remediation
Install update from vendor's website.