ID

VAR-201411-0175


CVE

CVE-2014-8652


TITLE

Elipse E3 Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-005320

DESCRIPTION

Elipse E3 3.x and earlier allows remote attackers to cause a denial of service (application crash and plant outage) via a rapid series of HTTP requests to index.html on TCP port 1681. The Elipse E3 is a monitoring control and data acquisition system. Elipse has a denial of service vulnerability. An attacker could exploit this vulnerability to initiate a denial of service attack. E3 3.2 and prior versions are vulnerable. Elipse Software E3 is a set of HMI/SCADA platform that provides support for distributed applications, mission-critical applications and control centers from Elipse Software in Brazil

Trust: 2.52

sources: NVD: CVE-2014-8652 // JVNDB: JVNDB-2014-005320 // CNVD: CNVD-2014-08214 // BID: 71322 // VULHUB: VHN-76597

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-08214

AFFECTED PRODUCTS

vendor:elipsemodel:e3scope:eqversion:3.2

Trust: 1.2

vendor:elipsemodel:e3scope:lteversion:3.2

Trust: 1.0

vendor:elipsemodel:e3scope:lteversion:3.x

Trust: 0.8

vendor:elipsemodel:e3scope:ltversion:3.2

Trust: 0.6

vendor:elipsemodel:software e3scope:eqversion:3.2

Trust: 0.3

vendor:elipsemodel:software e3scope:eqversion:3.0

Trust: 0.3

sources: CNVD: CNVD-2014-08214 // BID: 71322 // JVNDB: JVNDB-2014-005320 // CNNVD: CNNVD-201411-125 // NVD: CVE-2014-8652

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-8652
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-8652
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-08214
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201411-125
value: MEDIUM

Trust: 0.6

VULHUB: VHN-76597
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-8652
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-08214
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-76597
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-08214 // VULHUB: VHN-76597 // JVNDB: JVNDB-2014-005320 // CNNVD: CNNVD-201411-125 // NVD: CVE-2014-8652

PROBLEMTYPE DATA

problemtype:CWE-16

Trust: 1.9

sources: VULHUB: VHN-76597 // JVNDB: JVNDB-2014-005320 // NVD: CVE-2014-8652

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201411-125

TYPE

configuration error

Trust: 0.6

sources: CNNVD: CNNVD-201411-125

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-005320

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-76597

PATCH

title:E3 Sobre o E3url:http://www.elipse.com.br/port/e3.aspx

Trust: 0.8

title:Elipse denial of service vulnerability patchurl:https://www.cnvd.org.cn/patchInfo/show/51791

Trust: 0.6

sources: CNVD: CNVD-2014-08214 // JVNDB: JVNDB-2014-005320

EXTERNAL IDS

db:NVDid:CVE-2014-8652

Trust: 3.4

db:JVNDBid:JVNDB-2014-005320

Trust: 0.8

db:CNNVDid:CNNVD-201411-125

Trust: 0.7

db:CNVDid:CNVD-2014-08214

Trust: 0.6

db:BIDid:71322

Trust: 0.4

db:EXPLOIT-DBid:35379

Trust: 0.1

db:VULHUBid:VHN-76597

Trust: 0.1

sources: CNVD: CNVD-2014-08214 // VULHUB: VHN-76597 // BID: 71322 // JVNDB: JVNDB-2014-005320 // CNNVD: CNNVD-201411-125 // NVD: CVE-2014-8652

REFERENCES

url:http://seclists.org/fulldisclosure/2014/jul/69

Trust: 3.1

url:http://firebitsbr.wordpress.com/2014/07/16/vsla-security-advisory-fire-scada-dos-2013-001-http-dos-requests-flooding-crash-device-vulnerabilities-elipse-e3-scada-plc/

Trust: 2.0

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-8652

Trust: 1.4

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-8652

Trust: 0.8

url:http://www.elipse.com.br/port/e3.aspx

Trust: 0.3

sources: CNVD: CNVD-2014-08214 // VULHUB: VHN-76597 // BID: 71322 // JVNDB: JVNDB-2014-005320 // CNNVD: CNNVD-201411-125 // NVD: CVE-2014-8652

CREDITS

firebitsbr

Trust: 0.3

sources: BID: 71322

SOURCES

db:CNVDid:CNVD-2014-08214
db:VULHUBid:VHN-76597
db:BIDid:71322
db:JVNDBid:JVNDB-2014-005320
db:CNNVDid:CNNVD-201411-125
db:NVDid:CVE-2014-8652

LAST UPDATE DATE

2025-04-13T23:39:40.854000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-08214date:2015-05-07T00:00:00
db:VULHUBid:VHN-76597date:2014-11-14T00:00:00
db:BIDid:71322date:2014-11-10T00:00:00
db:JVNDBid:JVNDB-2014-005320date:2014-11-11T00:00:00
db:CNNVDid:CNNVD-201411-125date:2014-11-14T00:00:00
db:NVDid:CVE-2014-8652date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-08214date:2014-11-12T00:00:00
db:VULHUBid:VHN-76597date:2014-11-10T00:00:00
db:BIDid:71322date:2014-11-10T00:00:00
db:JVNDBid:JVNDB-2014-005320date:2014-11-11T00:00:00
db:CNNVDid:CNNVD-201411-125date:2014-11-14T00:00:00
db:NVDid:CVE-2014-8652date:2014-11-10T11:55:09.970