ID

VAR-201304-0146


CVE

CVE-2013-0683


TITLE

plural Cogent Real-Time Systems Service disruption in products (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2013-002157

DESCRIPTION

The DataSim and DataPid demonstration clients in Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 allow remote servers to cause a denial of service (incorrect pointer access and client crash) via malformed data in a formatted text command. Cogent Real-Time Systems is a real-time data solutions vendor. If the user connects DataSim or DataPid to the server instead of DataHub, the server design generates a random or malformed message, then DataSim and DataPid will crash. Successfully exploiting this issue will result in a denial-of-service condition

Trust: 2.61

sources: NVD: CVE-2013-0683 // JVNDB: JVNDB-2013-002157 // CNVD: CNVD-2013-02822 // BID: 58909 // IVD: 0388d7d4-2353-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 0388d7d4-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-02822

AFFECTED PRODUCTS

vendor:cogentdatahubmodel:cogent datahubscope:eqversion:7.1.1

Trust: 1.6

vendor:cogentdatahubmodel:cascade datahubscope:eqversion:6.4.20

Trust: 1.6

vendor:cogentdatahubmodel:cogent datahubscope:eqversion:7.1.1.63

Trust: 1.6

vendor:cogentdatahubmodel:cogent datahubscope:eqversion:7.1.2

Trust: 1.6

vendor:cogentdatahubmodel:cogent datahubscope:eqversion:7.1.0

Trust: 1.6

vendor:cogentdatahubmodel:opc datahubscope:eqversion:6.4.20

Trust: 1.6

vendor:cogentdatahubmodel:datahub quicktrendscope:lteversion:7.2.2

Trust: 1.0

vendor:cogentdatahubmodel:opc datahubscope:lteversion:6.4.21

Trust: 1.0

vendor:cogentdatahubmodel:cogent datahubscope:lteversion:7.2.2

Trust: 1.0

vendor:cogentdatahubmodel:cascade datahubscope:lteversion:6.4.21

Trust: 1.0

vendor:cogentdatahubmodel:cogent datahubscope:eqversion:7.0.2

Trust: 1.0

vendor:cogentdatahubmodel:cogent datahubscope:eqversion:7.0

Trust: 1.0

vendor:cogent real timemodel:cascade datahubscope:ltversion:6.4.22

Trust: 0.8

vendor:cogent real timemodel:datahubscope:ltversion:7.3.0

Trust: 0.8

vendor:cogent real timemodel:datahub quicktrendscope:ltversion:7.3.0

Trust: 0.8

vendor:cogent real timemodel:opc datahubscope:ltversion:6.4.22

Trust: 0.8

vendor:cogentmodel:real-time systems opc datahubscope:eqversion:6.4.21

Trust: 0.6

vendor:cogentmodel:real-time systems cascade datahubscope:eqversion:6.4.21

Trust: 0.6

vendor:cogentmodel:real-time systems cogent datahubscope:eqversion:7.2.2

Trust: 0.6

vendor:cogentmodel:real-time systems datahub quicktrendscope:eqversion:7.2.2

Trust: 0.6

vendor:cogentmodel:real-time systems datapidscope:eqversion:7.2.2

Trust: 0.6

vendor:cogentmodel:real-time systems datapidscope:eqversion:6.4.21

Trust: 0.6

vendor:cogentmodel:real-time systems datasimscope:eqversion:7.2.2

Trust: 0.6

vendor:cogentmodel:real-time systems datasimscope:eqversion:6.4.21

Trust: 0.6

vendor:cogentdatahubmodel:datahub quicktrendscope:eqversion:7.2.2

Trust: 0.6

vendor:cogentdatahubmodel:cogent datahubscope:eqversion:7.2.2

Trust: 0.6

vendor:cogentdatahubmodel:cascade datahubscope:eqversion:6.4.21

Trust: 0.6

vendor:cogentdatahubmodel:opc datahubscope:eqversion:6.4.21

Trust: 0.6

vendor:cogentmodel:real-time systems opc datahubscope:eqversion:6.4.20

Trust: 0.3

vendor:cogentmodel:real-time systems opc datahubscope:eqversion:6.0.2

Trust: 0.3

vendor:cogentmodel:real-time systems opc datahubscope:eqversion:6

Trust: 0.3

vendor:cogentmodel:real-time systems cogent datahubscope:eqversion:7.1.2

Trust: 0.3

vendor:cogentmodel:real-time systems cogent datahubscope:eqversion:7.1.1.63

Trust: 0.3

vendor:cogentmodel:real-time systems cogent datahubscope:eqversion:7

Trust: 0.3

vendor:cogent datahubmodel: - scope:eqversion:7.0

Trust: 0.2

vendor:cogent datahubmodel: - scope:eqversion:7.0.2

Trust: 0.2

vendor:cogent datahubmodel: - scope:eqversion:7.1.0

Trust: 0.2

vendor:cogent datahubmodel: - scope:eqversion:7.1.1

Trust: 0.2

vendor:cogent datahubmodel: - scope:eqversion:7.1.1.63

Trust: 0.2

vendor:cogent datahubmodel: - scope:eqversion:7.1.2

Trust: 0.2

vendor:cogent datahubmodel: - scope:eqversion:*

Trust: 0.2

vendor:opc datahubmodel: - scope:eqversion:6.4.20

Trust: 0.2

vendor:opc datahubmodel: - scope:eqversion:*

Trust: 0.2

vendor:cascade datahubmodel: - scope:eqversion:6.4.20

Trust: 0.2

vendor:cascade datahubmodel: - scope:eqversion:*

Trust: 0.2

vendor:datahub quicktrendmodel: - scope:eqversion:*

Trust: 0.2

sources: IVD: 0388d7d4-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-02822 // BID: 58909 // JVNDB: JVNDB-2013-002157 // CNNVD: CNNVD-201304-033 // NVD: CVE-2013-0683

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-0683
value: HIGH

Trust: 1.0

NVD: CVE-2013-0683
value: HIGH

Trust: 0.8

CNVD: CNVD-2013-02822
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201304-033
value: HIGH

Trust: 0.6

IVD: 0388d7d4-2353-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

nvd@nist.gov: CVE-2013-0683
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2013-02822
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 0388d7d4-2353-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 0388d7d4-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-02822 // JVNDB: JVNDB-2013-002157 // CNNVD: CNNVD-201304-033 // NVD: CVE-2013-0683

PROBLEMTYPE DATA

problemtype:CWE-16

Trust: 1.8

sources: JVNDB: JVNDB-2013-002157 // NVD: CVE-2013-0683

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201304-033

TYPE

Configuration error

Trust: 0.8

sources: IVD: 0388d7d4-2353-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201304-033

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-002157

PATCH

title:Cogent DataHuburl:http://www.cogentdatahub.com/Products/Cogent_DataHub.html

Trust: 0.8

title:OPC DataHuburl:http://www.cogentdatahub.com/Products/OPC_DataHub.html

Trust: 0.8

title:Cascade DataHuburl:http://www.cogentdatahub.com/Products/Cascade_DataHub.html

Trust: 0.8

title:DataHub QuickTrendurl:http://www.cogentdatahub.com/Products/DataHub_QuickTrend.html

Trust: 0.8

title:Release Notesurl:http://www.cogentdatahub.com/ReleaseNotes.html

Trust: 0.8

title:Download Softwareurl:http://www.cogentdatahub.com/Contact_Form.html

Trust: 0.8

title:TopPageurl:http://www.cogentdatahub.com/jp/

Trust: 0.8

title:Patch for Cogent Real-Time Systems DataHub Remote Denial of Service Vulnerability (CNVD-2013-02822)url:https://www.cnvd.org.cn/patchInfo/show/33173

Trust: 0.6

title:OPCDataHub-6.4.22-130302-Windowsurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=45674

Trust: 0.6

title:CogentDataHub-7.3.0-130328-Windowsurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=45673

Trust: 0.6

sources: CNVD: CNVD-2013-02822 // JVNDB: JVNDB-2013-002157 // CNNVD: CNNVD-201304-033

EXTERNAL IDS

db:NVDid:CVE-2013-0683

Trust: 3.5

db:ICS CERTid:ICSA-13-095-01

Trust: 3.3

db:BIDid:58909

Trust: 0.9

db:CNVDid:CNVD-2013-02822

Trust: 0.8

db:CNNVDid:CNNVD-201304-033

Trust: 0.8

db:JVNDBid:JVNDB-2013-002157

Trust: 0.8

db:IVDid:0388D7D4-2353-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 0388d7d4-2353-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-02822 // BID: 58909 // JVNDB: JVNDB-2013-002157 // CNNVD: CNNVD-201304-033 // NVD: CVE-2013-0683

REFERENCES

url:http://ics-cert.us-cert.gov/pdf/icsa-13-095-01.pdf

Trust: 3.3

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-0683

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-0683

Trust: 0.8

url:http://www.cogentdatahub.com/products/cogent_datahub.html

Trust: 0.3

sources: CNVD: CNVD-2013-02822 // BID: 58909 // JVNDB: JVNDB-2013-002157 // CNNVD: CNNVD-201304-033 // NVD: CVE-2013-0683

CREDITS

Dillon Beresford

Trust: 0.3

sources: BID: 58909

SOURCES

db:IVDid:0388d7d4-2353-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2013-02822
db:BIDid:58909
db:JVNDBid:JVNDB-2013-002157
db:CNNVDid:CNNVD-201304-033
db:NVDid:CVE-2013-0683

LAST UPDATE DATE

2024-11-23T21:55:36.453000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-02822date:2013-05-22T00:00:00
db:BIDid:58909date:2015-03-19T09:11:00
db:JVNDBid:JVNDB-2013-002157date:2013-04-09T00:00:00
db:CNNVDid:CNNVD-201304-033date:2013-04-07T00:00:00
db:NVDid:CVE-2013-0683date:2024-11-21T01:48:00.233

SOURCES RELEASE DATE

db:IVDid:0388d7d4-2353-11e6-abef-000c29c66e3ddate:2013-04-09T00:00:00
db:CNVDid:CNVD-2013-02822date:2013-04-09T00:00:00
db:BIDid:58909date:2013-04-05T00:00:00
db:JVNDBid:JVNDB-2013-002157date:2013-04-09T00:00:00
db:CNNVDid:CNNVD-201304-033date:2013-04-07T00:00:00
db:NVDid:CVE-2013-0683date:2013-04-05T21:55:00.880