ID

VAR-201308-0165


CVE

CVE-2013-2790


TITLE

IOServer of master-station DNP3 Service disruption in drivers (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2013-003717

DESCRIPTION

The master-station DNP3 driver before driver19.exe, and Beta2041.exe, in IOServer allows remote attackers to cause a denial of service (infinite loop) via crafted DNP3 packets to TCP port 20000. IOServer is a Windows-based OPC server that allows OPC clients such as human-machine interfaces and monitoring and data acquisition systems to exchange factory data with programmable logic circuits. The IOServer driver does not verify or correctly verify the input on the primary server on port 20000/TCP, which can affect the control flow or database flow of the program. When an attacker can submit a special request to make the IOServer enter an infinite loop without exiting, you need to manually restart to get the normal function. Multiple IOServer drivers are prone to a remote denial-of-service vulnerability. This will result in a denial-of-service condition

Trust: 2.61

sources: NVD: CVE-2013-2790 // JVNDB: JVNDB-2013-003717 // CNVD: CNVD-2013-11627 // BID: 61577 // IVD: c86a2036-2352-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.2

sources: IVD: c86a2036-2352-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-11627

AFFECTED PRODUCTS

vendor:ioservermodel:ioserverscope:eqversion: -

Trust: 1.6

vendor:ioservermodel:ioserverscope:eqversion:master-station dnp3 driver beta2041.exe

Trust: 0.8

vendor:ioservermodel:ioserverscope:ltversion:master-station dnp3 driver driver19.exe

Trust: 0.8

vendor:ioservermodel:beta driverscope: - version: -

Trust: 0.6

vendor:ioservermodel: - scope:eqversion: -

Trust: 0.2

sources: IVD: c86a2036-2352-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-11627 // JVNDB: JVNDB-2013-003717 // CNNVD: CNNVD-201308-109 // NVD: CVE-2013-2790

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-2790
value: HIGH

Trust: 1.0

NVD: CVE-2013-2790
value: HIGH

Trust: 0.8

CNVD: CNVD-2013-11627
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201308-109
value: HIGH

Trust: 0.6

IVD: c86a2036-2352-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

nvd@nist.gov: CVE-2013-2790
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2013-11627
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: c86a2036-2352-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: c86a2036-2352-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-11627 // JVNDB: JVNDB-2013-003717 // CNNVD: CNNVD-201308-109 // NVD: CVE-2013-2790

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.8

sources: JVNDB: JVNDB-2013-003717 // NVD: CVE-2013-2790

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201308-109

TYPE

Input validation

Trust: 0.8

sources: IVD: c86a2036-2352-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201308-109

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-003717

PATCH

title:Top Pageurl:http://www.ioserver.com/

Trust: 0.8

title:Multiple IOServer Drivers denial of service vulnerability patchesurl:https://www.cnvd.org.cn/patchInfo/show/38038

Trust: 0.6

sources: CNVD: CNVD-2013-11627 // JVNDB: JVNDB-2013-003717

EXTERNAL IDS

db:NVDid:CVE-2013-2790

Trust: 3.5

db:ICS CERTid:ICSA-13-213-03

Trust: 3.0

db:BIDid:61577

Trust: 1.5

db:CNVDid:CNVD-2013-11627

Trust: 0.8

db:CNNVDid:CNNVD-201308-109

Trust: 0.8

db:JVNDBid:JVNDB-2013-003717

Trust: 0.8

db:IVDid:C86A2036-2352-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: c86a2036-2352-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-11627 // BID: 61577 // JVNDB: JVNDB-2013-003717 // CNNVD: CNNVD-201308-109 // NVD: CVE-2013-2790

REFERENCES

url:http://ics-cert.us-cert.gov/advisories/icsa-13-213-03

Trust: 3.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-2790

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-2790

Trust: 0.8

url:http://www.securityfocus.com/bid/61577

Trust: 0.6

sources: CNVD: CNVD-2013-11627 // JVNDB: JVNDB-2013-003717 // CNNVD: CNNVD-201308-109 // NVD: CVE-2013-2790

CREDITS

Adam Crain and Chris Sistrunk

Trust: 0.9

sources: BID: 61577 // CNNVD: CNNVD-201308-109

SOURCES

db:IVDid:c86a2036-2352-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2013-11627
db:BIDid:61577
db:JVNDBid:JVNDB-2013-003717
db:CNNVDid:CNNVD-201308-109
db:NVDid:CVE-2013-2790

LAST UPDATE DATE

2025-04-11T23:15:25.658000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-11627date:2013-08-06T00:00:00
db:BIDid:61577date:2013-10-21T00:18:00
db:JVNDBid:JVNDB-2013-003717date:2013-08-14T00:00:00
db:CNNVDid:CNNVD-201308-109date:2013-08-14T00:00:00
db:NVDid:CVE-2013-2790date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:IVDid:c86a2036-2352-11e6-abef-000c29c66e3ddate:2013-08-06T00:00:00
db:CNVDid:CNVD-2013-11627date:2013-08-06T00:00:00
db:BIDid:61577date:2013-08-01T00:00:00
db:JVNDBid:JVNDB-2013-003717date:2013-08-14T00:00:00
db:CNNVDid:CNNVD-201308-109date:2013-08-14T00:00:00
db:NVDid:CVE-2013-2790date:2013-08-13T15:04:18.597