CVE-2013-2796
published 2013-08-09CVE-2013-2796: Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read arbitrary…
PriorityP428medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.73%
50.0th percentile
Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | citectscada | <= 7.20 | — |
| schneider-electric | citectscada | — | — |
| schneider-electric | powerlogic_scada | <= 7.20 | — |
| schneider-electric | powerlogic_scada | — | — |
| schneider-electric | vijeo_citect | <= 7.20 | — |
| schneider-electric | vijeo_citect | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Vijeo Citect, CitectSCADA, PowerLogic SCADA Vulnerability
cisa_ics·2013-08-06
Schneider Electric Vijeo Citect, CitectSCADA, PowerLogic SCADA Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Vijeo Citect, CitectSCADA, PowerLogic SCADA Vulnerability
Last RevisedAugust 06, 2013
Alert CodeICSA-13-217-02
## Overview
Schneider Electric has identified an XML external entity vulnerability in Vijeo Citect, CitectSCADA, and PowerLogic SCADA applications. Timur Yunusov, Alexey Osipov, and Ilya Karpov of Positive Technologies reported the vulnerability directly to Schneider Electric. Schneider Electric has produced patches that mitigate this vulnerability.
## Affected Products
Schneider Electric reports that the vulnerability affects the following products
GHSA
GHSA-fxqp-5cfq-qj7q: Schneider Electric Vijeo Citect 7
ghsa_unreviewed·2022-05-17
CVE-2013-2796 [MEDIUM] GHSA-fxqp-5cfq-qj7q: Schneider Electric Vijeo Citect 7
Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-08-09
Published