CVE-2013-2824
published 2014-02-26CVE-2013-2824: Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare PowerSCADA…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.79%
75.8th percentile
Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare PowerSCADA Expert 7.30 through 7.30SR1, and PowerLogic SCADA 7.20 through 7.20SR1 do not properly handle exceptions, which allows remote attackers to cause a denial of service via a crafted packet.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | citectscada | — | — |
| schneider-electric | citectscada | — | — |
| schneider-electric | powerlogic_scada | — | — |
| schneider-electric | struxureware_powerscada_expert | — | — |
| schneider-electric | struxureware_scada_expert_vijeo_citect | — | — |
| schneider-electric | struxureware_scada_expert_vijeo_citect | — | — |
| schneider-electric | struxureware_scada_expert_vijeo_citect | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hcf2-m3fc-44v4: Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7
ghsa_unreviewed·2022-05-17
CVE-2013-2824 [HIGH] GHSA-hcf2-m3fc-44v4: Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7
Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare PowerSCADA Expert 7.30 through 7.30SR1, and PowerLogic SCADA 7.20 through 7.20SR1 do not properly handle exceptions, which allows remote attackers to cause a denial of service via a crafted packet.
CISA ICS
Schneider Electric CitectSCADA Products Exception Handler Vulnerability (Update A)
cisa_ics·2018-09-06
Schneider Electric CitectSCADA Products Exception Handler Vulnerability (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric CitectSCADA Products Exception Handler Vulnerability (Update A)
Last RevisedSeptember 06, 2018
Alert CodeICSA-13-350-01A
## OVERVIEW
## --------- Begin Update A Part 1 of 1 --------
This updated advisory is a follow-up to the original advisory titled ICSA-13-350-01 Schneider Electric SCADA Products Exception Handler Vulnerability that was published February 25, 2014, on the NCCIC/ICS-CERT web site. This advisory was originally posted to the US-CERT secure Portal library on December 16, 2013. Schneider Electric requested the title change to reduce confusion.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-02-26
Published