CVE-2020-10613
Triangle MicroWorks SCADA Data Gateway DNP3 Out-Of-Bounds Read Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to disclose sensitive information due to the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. Authentication is not required to exploit this vulnerability. Only applicable to installations using DNP3 Data Sets.
Triangle MicroWorks SCADA Data Gateway versiones 3.02.0697 hasta 4.0.122, versiones 2.41.0213 hasta 4.0.122, permite a atacantes remotos divulgar información confidencial debido a la falta de comprobación apropiada de los datos suministrados por el usuario, lo que puede resultar en una lectura más allá del final de una estructura asignada. No es requerida una autenticación para explotar esta vulnerabilidad. Solo aplicable a instalaciones que utilizan DNP3 Data Sets.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability.
The specific flaw exists with the handling of data set descriptors. The issue results from the lack of proper validation of user-supplied data which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of SYSTEM.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-03-16 CVE Reserved
- 2020-04-15 CVE Published
- 2024-04-22 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.us-cert.gov/ics/advisories/icsa-20-105-03 | Third Party Advisory | |
https://www.zerodayinitiative.com/advisories/ZDI-20-548 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trianglemicroworks Search vendor "Trianglemicroworks" | Scada Data Gateway Search vendor "Trianglemicroworks" for product "Scada Data Gateway" | >= 2.41.0213 <= 4.0.122 Search vendor "Trianglemicroworks" for product "Scada Data Gateway" and version " >= 2.41.0213 <= 4.0.122" | - |
Affected
|