cve/2020/CVE-2020-10611.md

19 lines
1.0 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2020-10611](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10611)
![](https://img.shields.io/static/v1?label=Product&message=Triangle%20MicroWorks%20SCADA%20Data%20Gateway%203.02.0697%20through%204.0.122%2C%202.41.0213%20through%204.0.122&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=ACCESS%20OF%20RESOURCE%20USING%20INCOMPATIBLE%20TYPE%20('TYPE%20CONFUSION')%20CWE-843&color=brighgreen)
### Description
Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type confusion condition. Authentication is not required to exploit this vulnerability. Only applicable to installations using DNP3 Data Sets.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/alphaSeclab/sec-daily-2020
- https://github.com/neutrinoguy/awesome-ics-writeups