VYPR
Unrated severityNVD Advisory· Published Jun 5, 2014· Updated May 6, 2026

CVE-2014-2345

CVE-2014-2345

Description

A crafted DNP3 packet causes an infinite loop and crash in COPA-DATA zenon DNP3 drivers, enabling remote denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A crafted DNP3 packet causes an infinite loop and crash in COPA-DATA zenon DNP3 drivers, enabling remote denial of service.

Vulnerability

The vulnerability is an improper input validation (CWE-20) in the COPA-DATA zenon DNP3 NG driver (DNP3 master) versions 7.10 SP0 up to and including 7.11 SP0 build 10238, and the zenon DNP3 Process Gateway (DNP3 outstation) versions 7.11 SP0 build 10238 and prior [1][2]. The flaw resides in the handling of DNP3 packets received over TCP. By sending a specially crafted DNP3 packet, an attacker can trigger an infinite loop in the driver, leading to a process crash.

Exploitation

An attacker can exploit this vulnerability remotely by sending a single crafted DNP3 packet over TCP to an affected device. No authentication or prior access is required. The packet causes the DNP3 driver to enter an infinite loop, consuming CPU resources and eventually crashing the process [1][2].

Impact

Successful exploitation results in a denial-of-service (DoS) condition. The crash closes all communication connections and causes system instability, potentially disrupting SCADA operations in energy, water, and wastewater treatment environments [1][2]. No code execution or data compromise is reported.

Mitigation

COPA-DATA has produced an update that mitigates the vulnerability. Affected users should contact COPA-DATA support to obtain the patch [1][2]. No workaround is provided. This vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

8
  • cpe:2.3:a:copadata:zenon_dnp3_ng_driver:7.10:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:copadata:zenon_dnp3_ng_driver:7.10:*:*:*:*:*:*:*
    • cpe:2.3:a:copadata:zenon_dnp3_ng_driver:7.11:-:*:*:*:*:*:*
    • cpe:2.3:a:copadata:zenon_dnp3_ng_driver:7.11:sp0_build_10238:*:*:*:*:*:*
    • (no CPE)range: <= 7.11 SP0 build 10238
  • cpe:2.3:a:copadata:zenon_dnp3_process_gateway:7.11:sp0_build_10238:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:copadata:zenon_dnp3_process_gateway:7.11:sp0_build_10238:*:*:*:*:*:*
    • (no CPE)range: <= 7.11 SP0 build 10238
    • (no CPE)range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.