CVE-2014-2345
Description
A crafted DNP3 packet causes an infinite loop and crash in COPA-DATA zenon DNP3 drivers, enabling remote denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A crafted DNP3 packet causes an infinite loop and crash in COPA-DATA zenon DNP3 drivers, enabling remote denial of service.
Vulnerability
The vulnerability is an improper input validation (CWE-20) in the COPA-DATA zenon DNP3 NG driver (DNP3 master) versions 7.10 SP0 up to and including 7.11 SP0 build 10238, and the zenon DNP3 Process Gateway (DNP3 outstation) versions 7.11 SP0 build 10238 and prior [1][2]. The flaw resides in the handling of DNP3 packets received over TCP. By sending a specially crafted DNP3 packet, an attacker can trigger an infinite loop in the driver, leading to a process crash.
Exploitation
An attacker can exploit this vulnerability remotely by sending a single crafted DNP3 packet over TCP to an affected device. No authentication or prior access is required. The packet causes the DNP3 driver to enter an infinite loop, consuming CPU resources and eventually crashing the process [1][2].
Impact
Successful exploitation results in a denial-of-service (DoS) condition. The crash closes all communication connections and causes system instability, potentially disrupting SCADA operations in energy, water, and wastewater treatment environments [1][2]. No code execution or data compromise is reported.
Mitigation
COPA-DATA has produced an update that mitigates the vulnerability. Affected users should contact COPA-DATA support to obtain the patch [1][2]. No workaround is provided. This vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
8cpe:2.3:a:copadata:zenon_dnp3_ng_driver:7.10:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:copadata:zenon_dnp3_ng_driver:7.10:*:*:*:*:*:*:*
- cpe:2.3:a:copadata:zenon_dnp3_ng_driver:7.11:-:*:*:*:*:*:*
- cpe:2.3:a:copadata:zenon_dnp3_ng_driver:7.11:sp0_build_10238:*:*:*:*:*:*
- (no CPE)range: <= 7.11 SP0 build 10238
cpe:2.3:a:copadata:zenon_dnp3_process_gateway:7.11:sp0_build_10238:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:copadata:zenon_dnp3_process_gateway:7.11:sp0_build_10238:*:*:*:*:*:*
- (no CPE)range: <= 7.11 SP0 build 10238
- (no CPE)range: 0
- Range: 7.10 SP0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.