Vulnerability CVE-2013-0689


Published: 2013-10-03

Description:
The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to upload files and consequently execute arbitrary code via unspecified vectors.

Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
ENEA -> OSE 
Emerson -> Dl 8000 remote terminal unit 
Emerson -> Roc 800 remote terminal unit 
Emerson -> Roc 800l remote terminal unit 

 References:
http://ics-cert.us-cert.gov/advisories/ICSA-13-259-01

Copyright 2024, cxsecurity.com

 

Back to Top