The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffer overflow vulnerability that could result in a server-side crash.
References
Link | Resource |
---|---|
https://www.us-cert.gov/ics/advisories/icsa-19-290-01 | Third Party Advisory US Government Resource |
https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec139.pdf | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2020-01-14 11:15
Updated : 2020-02-10 13:50
NVD link : CVE-2019-13537
Mitre link : CVE-2019-13537
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
aveva
- iec870ip_firmware
- iec870ip