CVE-2013-2796
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Schneider Electric Vijeo Citect v7.20 y anteriores, CitectSCADA v7.20 y anteriores, y PowerLogic SCADA v7.20 y anteriores, permite a atacantes remotos leer ficheros, enviar peticiones HTTP a servidores intranet, o causar una denegación del servicio (consumo de CPU y memoria) a través de fichero XML que contiene una declaración de entidad externa, junto con una referencia de entidad, en relación con un fallo en XML External Entity (XXE).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-04-11 CVE Reserved
- 2013-08-09 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://ics-cert.us-cert.gov/advisories/ICSA-13-217-02 | Us Government Resource |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.citect.schneider-electric.com/cs-HF720SP459363 | 2013-08-12 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Schneider-electric Search vendor "Schneider-electric" | Citectscada Search vendor "Schneider-electric" for product "Citectscada" | <= 7.20 Search vendor "Schneider-electric" for product "Citectscada" and version " <= 7.20" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Citectscada Search vendor "Schneider-electric" for product "Citectscada" | 7.10 Search vendor "Schneider-electric" for product "Citectscada" and version "7.10" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Powerlogic Scada Search vendor "Schneider-electric" for product "Powerlogic Scada" | <= 7.20 Search vendor "Schneider-electric" for product "Powerlogic Scada" and version " <= 7.20" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Powerlogic Scada Search vendor "Schneider-electric" for product "Powerlogic Scada" | 7.10 Search vendor "Schneider-electric" for product "Powerlogic Scada" and version "7.10" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Vijeo Citect Search vendor "Schneider-electric" for product "Vijeo Citect" | <= 7.20 Search vendor "Schneider-electric" for product "Vijeo Citect" and version " <= 7.20" | - |
Affected
| ||||||
Schneider-electric Search vendor "Schneider-electric" | Vijeo Citect Search vendor "Schneider-electric" for product "Vijeo Citect" | 7.10 Search vendor "Schneider-electric" for product "Vijeo Citect" and version "7.10" | - |
Affected
|