vendor:
Nano-10
by:
Sapling
7,5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Nano-10
Affected Version From: Firmware Version r81 and prior
Affected Version To: Firmware Version r81 and prior
Patch Exists: NO
Related CWE: CVE-2013-2784
CPE: h:tri-plc:nano-10
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Tri-PLC Nano-10 DoS
The vulnerability exists due to a flaw in the PLC's ability to handle a Modbus packet with the bit quantity of coils set to 0. When sending this malformed packet the device crashes and fails to recover without manual intervention. Once an engineer manually reboots the device it will recover from the crash.
Mitigation:
In order to minimize the risk of this attack the Modbus access control list can be used to limit the ip addresses that can connect to the device. Additionally, limiting this device to segmented internal networks is advised and blocking port TCP 502 at the gateway.