CVE-2020-10611
Triangle MicroWorks SCADA Data Gateway DNP3 Type Confusion Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type confusion condition. Authentication is not required to exploit this vulnerability. Only applicable to installations using DNP3 Data Sets.
Triangle MicroWorks SCADA Data Gateway versiones 3.02.0697 hasta 4.0.122, versiones 2.41.0213 hasta 4.0.122, permite a atacantes remotos ejecutar código arbitrario debido a la falta de comprobación apropiada de los datos suministrados por el usuario, lo que puede causar una condición de confusión de tipos. No es requerida una autenticación para explotar esta vulnerabilidad. Solo aplicable a instalaciones que utilizan DNP3 Data Sets.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of data set elements. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-03-16 CVE Reserved
- 2020-04-15 CVE Published
- 2024-08-04 CVE Updated
- 2024-10-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.us-cert.gov/ics/advisories/icsa-20-105-03 | Third Party Advisory | |
https://www.zerodayinitiative.com/advisories/ZDI-20-549 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trianglemicroworks Search vendor "Trianglemicroworks" | Scada Data Gateway Search vendor "Trianglemicroworks" for product "Scada Data Gateway" | >= 2.41.0213 <= 4.0.122 Search vendor "Trianglemicroworks" for product "Scada Data Gateway" and version " >= 2.41.0213 <= 4.0.122" | - |
Affected
|