Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2019-13537 |
CWE-ID | CWE-121 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
IEC870IP Hardware solutions / Drivers |
Vendor | AVEVA Software, LLC. |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU21935
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2019-13537
CWE-ID:
Exploit availability:
Description
The vulnerability allows a remote attacker to cause a server-side crash.
The vulnerability exists due to a boundary error in the IEC870IP driver. A remote unauthenticated attacker can trigger stack-based buffer overflow and cause a server-side crash on the target system.
Note: This vulnerability affects only the IEC870IP driver used in Vijeo Citect and Citect SCADA. MitigationInstall updates from vendor's website.
Vulnerable software versionsIEC870IP: 4.14.02
Fixed software versionsCPE2.3 External links
http://ics-cert.us-cert.gov/advisories/icsa-19-290-01
http://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec139.pdf
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?