Aveva Update
3442Warning Date
Severity Level
Warning Number
Target Sector
20 October, 2019
● High
2019-540
Energy
Description:
AVEVA has released a security update to address a vulnerability in the following product:
- IEC870IP driver v4.14.02 and earlier for Vijeo Citect and Citect SCADA
Threats:
Attacker could exploit this vulnerability by doing the following:
- Buffer overflow-remotely.
Best practice and Recommendations:
The CERT team encourages users to review AVEVA security advisory and apply the necessary Updates: https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec139.pdf