CVE-2013-2811: Catapultsoftware Catapult DNP3 I/o Driver
High severity, CVSS 7.1. EPSS: 1.8% chance of exploitation in the next 30 days.
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow remote attackers to cause a denial of service (infinite loop) via a crafted DNP3 TCP packet.
Affected products
- Catapultsoftware Catapult DNP3 I/o Driver: up to and including 7.20.56
- Ge Intelligent Platforms Proficy DNP3 I/o Driver: up to and including 7.20; version 7.20 only
- Ge Intelligent Platforms Proficy Hmi/scada Cimplicity: version 4.01 only; version 7.5 only; version 8.0 only; version 8.1 only; version 8.2 only
- Ge Intelligent Platforms Proficy Hmi/scada Ifix: version 5.0 only; version 5.1 only
Published 2013-11-22. Last modified 2026-06-16.