CVE-2014-9203
Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used in MACTek Bullet DTM 1.00.0, GE Vector DTM 1.00.0, GE SVi1000 Positioner DTM 1.00.0, GE SVI II AP Positioner DTM 2.00.1, and GE 12400…
Does this matter?
Lower severity and a low EPSS score (1.80%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used in MACTek Bullet DTM 1.00.0, GE Vector DTM 1.00.0, GE SVi1000 Positioner DTM 1.00.0, GE SVI II AP Positioner DTM 2.00.1, and GE 12400 Level Transmitter DTM 1.00.0, allows remote attackers to cause a denial of service (DTM outage) via crafted packets.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- ge/12400 level transmitter device type manager · ge/svi ii ap positioner device type manager · ge/vector device type manager · mactek/bullet device type manager
- Source
- ics-cert@hq.dhs.gov
References
- http://www.geoilandgas.com/securityadvisoryVendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-15-036-01Third Party Advisory, US Government Resource
- http://www.geoilandgas.com/securityadvisoryVendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-15-036-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.