CVE-2013-2822

NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow physically proximate attackers to cause a denial of service (driver crash and process restart) via crafted input over a serial line.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:novatech:orion5_dnp_master:1.27.38:*:*:*:*:*:*:*
cpe:2.3:h:novatech:orion5_dnp_slave:1.23.10:*:*:*:*:*:*:*
cpe:2.3:h:novatech:orion5r_dnp_master:1.27.38:*:*:*:*:*:*:*
cpe:2.3:h:novatech:orion5r_dnp_slave:1.23.10:*:*:*:*:*:*:*
cpe:2.3:h:novatech:orionlx_dnp_master:1.27.38:*:*:*:*:*:*:*
cpe:2.3:h:novatech:orionlx_dnp_slave:1.23.10:*:*:*:*:*:*:*

History

21 Nov 2024, 01:52

Type Values Removed Values Added
References () http://ics-cert.us-cert.gov/advisories/ICSA-13-352-01 - US Government Resource () http://ics-cert.us-cert.gov/advisories/ICSA-13-352-01 - US Government Resource

Information

Published : 2013-12-21 14:22

Updated : 2025-04-11 00:51


NVD link : CVE-2013-2822

Mitre link : CVE-2013-2822

CVE.ORG link : CVE-2013-2822


JSON object : View

Products Affected

novatech

  • orionlx_dnp_master
  • orion5_dnp_slave
  • orion5r_dnp_master
  • orionlx_dnp_slave
  • orion5_dnp_master
  • orion5r_dnp_slave
CWE
CWE-20

Improper Input Validation