ID

VAR-201405-0286


CVE

CVE-2014-2342


TITLE

Triangle MicroWorks SCADA Data Gateway Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-002710

DESCRIPTION

Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows remote attackers to cause a denial of service (excessive data processing) via a crafted DNP3 packet. Triangle MicroWorks is a US-based company that uses single or third-party component products to communicate with peripherals/slave devices using various transport protocols (OPC Client, IEC 60870-6 (TASE.2/ICCP) Client, IEC 60870-5, DNP3, Modbus). SCADA Data Gateway is prone to a remote denial-of-service vulnerability because the application fails to properly validate the user-supplied input. An attacker can leverage this issue to consume resources resulting in denial-of-service condition; denying service to legitimate users. Note: This issue affects the IP connected devices. Versions prior to SCADA Data Gateway 3.00.0635 are vulnerable. Triangle MicroWorks SCADA Data Gateway (SDG) is a set of data acquisition and supervisory control system (SCADA) gateway products integrated in the server of Triangle MicroWorks in the United States

Trust: 2.88

sources: NVD: CVE-2014-2342 // JVNDB: JVNDB-2014-002710 // CNVD: CNVD-2014-03461 // BID: 67722 // IVD: 7d711e00-463f-11e9-9c2c-000c29342cb1 // IVD: f3b5d68c-2351-11e6-abef-000c29c66e3d // VULHUB: VHN-70281

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 1.0

sources: IVD: 7d711e00-463f-11e9-9c2c-000c29342cb1 // IVD: f3b5d68c-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-03461

AFFECTED PRODUCTS

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:3.00.0630

Trust: 1.6

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:3.00.0616

Trust: 1.6

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.50

Trust: 1.6

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.53

Trust: 1.6

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:3.00.0612

Trust: 1.6

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.51

Trust: 1.6

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:3.00.0615

Trust: 1.6

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.50.0309

Trust: 1.6

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0583

Trust: 1.6

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0545

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0597

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0590

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0528

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0518

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0595

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0540

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0594

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0571

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0576

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0580

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0552

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0592

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0558

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0515

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0516

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0561

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0575

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0578

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0582

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0596

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0598

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0536

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0565

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0588

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0572

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0579

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0599

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0567

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:3.00

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0574

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:lteversion:3.00.0633

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0564

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0587

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0562

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0566

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0586

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0581

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0529

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0570

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0573

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0589

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0553

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0584

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0569

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0591

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0544

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0517

Trust: 1.0

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:2.54.0577

Trust: 1.0

vendor:triangle microworksmodel:scada data gatewayscope:ltversion:3.00.0635

Trust: 0.8

vendor:trianglemodel:microworks scada data gatewayscope: - version: -

Trust: 0.6

vendor:trianglemicroworksmodel:scada data gatewayscope:eqversion:3.00.0633

Trust: 0.6

vendor:scada data gatewaymodel: - scope:eqversion:2.50

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.50.0309

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.51

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.53

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0515

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0516

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0517

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0518

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0528

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0529

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0536

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0540

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0544

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0545

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0552

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0553

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0558

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0561

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0562

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0564

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0565

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0566

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0567

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0569

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0570

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0571

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0572

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0573

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0574

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0575

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0576

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0577

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0578

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0579

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0580

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0581

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0582

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0583

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0584

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0586

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0587

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0588

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0589

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0590

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0591

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0592

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0594

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0595

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0596

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0597

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0598

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:2.54.0599

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:3.00

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:3.00.0612

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:3.00.0615

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:3.00.0616

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:3.00.0630

Trust: 0.4

vendor:scada data gatewaymodel: - scope:eqversion:*

Trust: 0.4

vendor:trianglemodel:microworks scada data gatewayscope:eqversion:3.0.616

Trust: 0.3

vendor:trianglemodel:microworks scada data gatewayscope:neversion:3.0.635

Trust: 0.3

sources: IVD: 7d711e00-463f-11e9-9c2c-000c29342cb1 // IVD: f3b5d68c-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-03461 // BID: 67722 // CNNVD: CNNVD-201405-580 // JVNDB: JVNDB-2014-002710 // NVD: CVE-2014-2342

CVSS

SEVERITY

CVSSV2

CVSSV3

ics-cert@hq.dhs.gov: CVE-2014-2342
value: MEDIUM

Trust: 1.0

nvd@nist.gov: CVE-2014-2342
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-2342
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-03461
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201405-580
value: MEDIUM

Trust: 0.6

IVD: 7d711e00-463f-11e9-9c2c-000c29342cb1
value: MEDIUM

Trust: 0.2

IVD: f3b5d68c-2351-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

VULHUB: VHN-70281
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-2342
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

ics-cert@hq.dhs.gov: CVE-2014-2342
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

CNVD: CNVD-2014-03461
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 7d711e00-463f-11e9-9c2c-000c29342cb1
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

IVD: f3b5d68c-2351-11e6-abef-000c29c66e3d
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-70281
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: IVD: 7d711e00-463f-11e9-9c2c-000c29342cb1 // IVD: f3b5d68c-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-03461 // VULHUB: VHN-70281 // CNNVD: CNNVD-201405-580 // JVNDB: JVNDB-2014-002710 // NVD: CVE-2014-2342 // NVD: CVE-2014-2342

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

problemtype:CWE-400

Trust: 1.0

sources: VULHUB: VHN-70281 // JVNDB: JVNDB-2014-002710 // NVD: CVE-2014-2342

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201405-580

TYPE

Input validation

Trust: 1.0

sources: IVD: 7d711e00-463f-11e9-9c2c-000c29342cb1 // IVD: f3b5d68c-2351-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201405-580

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-002710

PATCH

title:SCADA Data Gatewayurl:http://www.trianglemicroworks.com/products/scada-data-gateway/what%27s-new

Trust: 0.8

title:Patch for SCADA Data Gateway IP Link Device Remote Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/46142

Trust: 0.6

sources: CNVD: CNVD-2014-03461 // JVNDB: JVNDB-2014-002710

EXTERNAL IDS

db:NVDid:CVE-2014-2342

Trust: 3.8

db:ICS CERTid:ICSA-14-149-01

Trust: 3.4

db:CNNVDid:CNNVD-201405-580

Trust: 1.1

db:CNVDid:CNVD-2014-03461

Trust: 1.0

db:BIDid:67722

Trust: 1.0

db:JVNDBid:JVNDB-2014-002710

Trust: 0.8

db:IVDid:7D711E00-463F-11E9-9C2C-000C29342CB1

Trust: 0.2

db:IVDid:F3B5D68C-2351-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:VULHUBid:VHN-70281

Trust: 0.1

sources: IVD: 7d711e00-463f-11e9-9c2c-000c29342cb1 // IVD: f3b5d68c-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-03461 // VULHUB: VHN-70281 // BID: 67722 // CNNVD: CNNVD-201405-580 // JVNDB: JVNDB-2014-002710 // NVD: CVE-2014-2342

REFERENCES

url:http://ics-cert.us-cert.gov/advisories/icsa-14-149-01

Trust: 3.4

url:http://www.trianglemicroworks.com/products/scada-data-gateway/what%27s-new

Trust: 1.7

url:https://www.cisa.gov/news-events/ics-advisories/icsa-14-149-01

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-2342

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-2342

Trust: 0.8

url:http://www.trianglemicroworks.com/

Trust: 0.3

url:http://www.trianglemicroworks.com/documents/mdnp_scl_whats_new.pdf

Trust: 0.3

sources: CNVD: CNVD-2014-03461 // VULHUB: VHN-70281 // BID: 67722 // CNNVD: CNNVD-201405-580 // JVNDB: JVNDB-2014-002710 // NVD: CVE-2014-2342

CREDITS

Adam Crain and Chris Sistrunk

Trust: 0.3

sources: BID: 67722

SOURCES

db:IVDid:7d711e00-463f-11e9-9c2c-000c29342cb1
db:IVDid:f3b5d68c-2351-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2014-03461
db:VULHUBid:VHN-70281
db:BIDid:67722
db:CNNVDid:CNNVD-201405-580
db:JVNDBid:JVNDB-2014-002710
db:NVDid:CVE-2014-2342

LAST UPDATE DATE

2025-10-03T23:19:08.092000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-03461date:2014-06-06T00:00:00
db:VULHUBid:VHN-70281date:2014-06-05T00:00:00
db:BIDid:67722date:2014-05-29T00:00:00
db:CNNVDid:CNNVD-201405-580date:2014-06-04T00:00:00
db:JVNDBid:JVNDB-2014-002710date:2014-06-03T00:00:00
db:NVDid:CVE-2014-2342date:2025-10-02T23:15:29

SOURCES RELEASE DATE

db:IVDid:7d711e00-463f-11e9-9c2c-000c29342cb1date:2014-06-06T00:00:00
db:IVDid:f3b5d68c-2351-11e6-abef-000c29c66e3ddate:2014-06-06T00:00:00
db:CNVDid:CNVD-2014-03461date:2014-06-05T00:00:00
db:VULHUBid:VHN-70281date:2014-05-30T00:00:00
db:BIDid:67722date:2014-05-29T00:00:00
db:CNNVDid:CNNVD-201405-580date:2014-05-30T00:00:00
db:JVNDBid:JVNDB-2014-002710date:2014-06-03T00:00:00
db:NVDid:CVE-2014-2342date:2014-05-30T23:55:02.707