No analysis available yet.
Vendor Solution
Subnet Solutions Inc. recommends users update PowerSYSTEM Center (PSC) to the latest versions: * PSC 2020 Update 25 * PSC 2024 For assistance with updating PSC, reach out directly to Subnet Solutions.
Vendor Workaround
If updating PSC is not possible, Subnet Solutions Inc recommends users apply the following mitigations to help reduce risk: * Disable Notification Service, Email Dispatch Service, or the outgoing email server in Notifications/Settings. * Configure PowerSYSTEM Center DCS network firewall to only allow connections to an approved and authorized email server. * Manage administrator access to PowerSYSTEM Center DCS operating system. * Monitor user activity records to ensure users are following acceptable usage policies of the application.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10826 | Subnet Solutions PowerSYSTEM Center's SMTPS notification service can be affected by importing an EC certificate with crafted F2m parameters, which can lead to excessive CPU consumption during the evaluation of the curve parameters. |
Fri, 11 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Subnet Solutions PowerSYSTEM Center's SMTPS notification service can be affected by importing an EC certificate with crafted F2m parameters, which can lead to excessive CPU consumption during the evaluation of the curve parameters. | |
| Title | Subnet Solutions PowerSYSTEM Center Out-of-Bounds Read | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-04-11T16:13:34.583Z
Reserved: 2025-04-08T00:02:45.758Z
Link: CVE-2025-31354
Updated: 2025-04-11T16:13:27.127Z
Status : Deferred
Published: 2025-04-11T16:15:19.800
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-31354
No data.
OpenCVE Enrichment
No data.
EUVD