7.8
CVSSv2

CVE-2013-2784

Published: 10/07/2013 Updated: 11/07/2013
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Triangle Research International (aka Tri) Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bounds checking of data in Modbus/TCP packets, which allows remote malicious users to cause a denial of service (networking outage) via a crafted packet to TCP port 502.

Vulnerable Product Search on Vulmon Subscribe to Product

triplc nano-10_plc_firmware

triplc nano-10_plc -

Exploits

# Exploit Title: Tri-PLC Nano-10 DoS # Date: 07/11/2013 # Exploit Author: Sapling # Vendor Homepage: wwwtri-plccom # Version: Firmware Version r81 and prior # CVE : CVE-2013-2784 # ICSA: ICSA-13-189-02 /* The vulnerability exists due to a flaw in the PLC's ability to handle a Modbus packet with the bit quantity of coils set to 0 When sending th ...
Tri-PLC Nano-10 r81 suffers from a denial of service vulnerability ...