CVE-2013-2822
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
21/12/2013
Last modified:
11/04/2025
Description
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow physically proximate attackers to cause a denial of service (driver crash and process restart) via crafted input over a serial line.
Impact
Base Score 2.0
4.70
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:h:novatech:orion5_dnp_master:1.27.38:*:*:*:*:*:*:* | ||
cpe:2.3:h:novatech:orion5_dnp_slave:1.23.10:*:*:*:*:*:*:* | ||
cpe:2.3:h:novatech:orion5r_dnp_master:1.27.38:*:*:*:*:*:*:* | ||
cpe:2.3:h:novatech:orion5r_dnp_slave:1.23.10:*:*:*:*:*:*:* | ||
cpe:2.3:h:novatech:orionlx_dnp_master:1.27.38:*:*:*:*:*:*:* | ||
cpe:2.3:h:novatech:orionlx_dnp_slave:1.23.10:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page