SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-9203

Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used in MACTek Bullet DTM 1.00.0, GE Vector DTM 1.00.0, GE SVi1000 Positioner DTM 1.00.0, GE SVI II AP Positioner DTM 2.00.1, and GE 12400…

MEDIUM 5.0EPSS 1.80%

Does this matter?

Lower severity and a low EPSS score (1.80%). Track it; it rarely justifies an emergency change on its own.

Description

Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used in MACTek Bullet DTM 1.00.0, GE Vector DTM 1.00.0, GE SVi1000 Positioner DTM 1.00.0, GE SVI II AP Positioner DTM 2.00.1, and GE 12400 Level Transmitter DTM 1.00.0, allows remote attackers to cause a denial of service (DTM outage) via crafted packets.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
1.80% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
ge/12400 level transmitter device type manager · ge/svi ii ap positioner device type manager · ge/vector device type manager · mactek/bullet device type manager
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.