4.7

CVE-2014-0762

CG Automation ePAQ-9410 Substation Gateway Improper Input Validation

The CG Automation Software DNP3 driver, used in the ePAQ-9410 Substation
 Gateway products, does not validate input correctly. An attacker could 
cause the software to go into an infinite loop, causing the process to 
crash. The system must be restarted manually to clear the condition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.257
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.7 3.4 6.9
AV:L/AC:M/Au:N/C:N/I:N/A:C
ics-cert@hq.dhs.gov 4.7 3.4 6.9
AV:L/AC:M/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://ics-cert.us-cert.gov/advisories/ICSA-14-238-01
US Government Resource
http://mail.cgautomationusa.com/login.aspx
https://www.cisa.gov/news-events/ics-advisories/icsa-14-238-01