Lucene search

K
cveIcscertCVE-2013-2810
HistoryDec 08, 2014 - 11:59 a.m.

CVE-2013-2810

2014-12-0811:59:00
CWE-77
icscert
web.nvd.nist.gov
40
emerson
process management
roc800
dl8000
roc800l
rtu
remote attackers
arbitrary commands
tcp replay attack
cve-2013-2810

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.006

Percentile

78.5%

Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary commands via a TCP replay attack.

Affected configurations

Nvd
Node
emersondl_8000_remote_terminal_unit_firmwareMatch2.30
AND
emersondl_8000_remote_terminal_unitMatch-
Node
emersonroc_800l_remote_terminal_unit_firmwareRange1.20
AND
emersonroc_800l_remote_terminal_unitMatch-
Node
emersonroc_800_remote_terminal_unit_firmwareRange3.50
AND
emersonroc_800_remote_terminal_unitMatch-
VendorProductVersionCPE
emersondl_8000_remote_terminal_unit_firmware2.30cpe:2.3:o:emerson:dl_8000_remote_terminal_unit_firmware:2.30:*:*:*:*:*:*:*
emersondl_8000_remote_terminal_unit-cpe:2.3:h:emerson:dl_8000_remote_terminal_unit:-:*:*:*:*:*:*:*
emersonroc_800l_remote_terminal_unit_firmware*cpe:2.3:o:emerson:roc_800l_remote_terminal_unit_firmware:*:*:*:*:*:*:*:*
emersonroc_800l_remote_terminal_unit-cpe:2.3:h:emerson:roc_800l_remote_terminal_unit:-:*:*:*:*:*:*:*
emersonroc_800_remote_terminal_unit_firmware*cpe:2.3:o:emerson:roc_800_remote_terminal_unit_firmware:*:*:*:*:*:*:*:*
emersonroc_800_remote_terminal_unit-cpe:2.3:h:emerson:roc_800_remote_terminal_unit:-:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.006

Percentile

78.5%

Related for CVE-2013-2810