Alstom manufactures industrial automation and control systems for critical infrastructure, with disclosed vulnerabilities concentrating in products such as e-terraControl and MiCOM S1 platforms that manage power distribution and protection operations. The observed weakness classes center on improper input validation, reflecting the protocol-parsing and command-interface exposure inherent to networked industrial equipment. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alstom over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2787HIGH Alstom e-terracontrol 3.5, 3.6, and 3.7 allows remote attackers to cause a denial of service (infinite loop) via crafted DNP3 packets. | Oct 13, 2013 | 7.8 | 24 | NO | NO |
CVE-2013-2786MEDIUM Alstom Grid MiCOM S1 Agile before 1.0.3 and Alstom Grid MiCOM S1 Studio use weak permissions for the MiCOM S1 %PROGRAMFILES% directory, which allows local users to gain privileges | Jul 10, 2013 | 6.6 | 20 | NO | NO |
CVE-2013-2818MEDIUM The DNP Master Driver in Alstom e-terracontrol 3.5, 3.6, and 3.7 allows physically proximate attackers to cause a denial of service (infinite loop and DNP3 service disruption) via | Dec 1, 2013 | 4.7 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alstom.
Media articles that mention a CVE ID that affects a product developed by Alstom — matched by CVE ID, not by vendor name.