10
CVSSv2

CVE-2011-3490

Published: 16/09/2011 Updated: 14/02/2012
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and previous versions allow remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a long command to port 11234, as demonstrated with the TF command.

Vulnerable Product Search on Vulmon Subscribe to Product

measuresoft scadapro

measuresoft scadapro 2.4.3

measuresoft scadapro 2.4.4

measuresoft scadapro 2.5.4

measuresoft scadapro 2.5.5

measuresoft scadapro 2.6.0

measuresoft scadapro 3.3.0

measuresoft scadapro 3.3.1

measuresoft scadapro 3.9.3

measuresoft scadapro 3.9.4

measuresoft scadapro 3.9.12

measuresoft scadapro 3.9.13

measuresoft scadapro 2.4.1

measuresoft scadapro 2.4.2

measuresoft scadapro 2.5.2

measuresoft scadapro 2.5.3

measuresoft scadapro 2.9.0

measuresoft scadapro 3.1.0

measuresoft scadapro 3.9.1

measuresoft scadapro 3.9.2

measuresoft scadapro 3.9.9

measuresoft scadapro 3.9.10

measuresoft scadapro 3.9.11

measuresoft scadapro 2.1

measuresoft scadapro 2.2

measuresoft scadapro 2.4.5

measuresoft scadapro 2.4.6

measuresoft scadapro 2.7.0

measuresoft scadapro 2.7.1

measuresoft scadapro 3.2.8

measuresoft scadapro 3.2.9

measuresoft scadapro 3.9.5

measuresoft scadapro 3.9.6

measuresoft scadapro 3.9.14

measuresoft scadapro 3.9.15

measuresoft scadapro 2.3

measuresoft scadapro 2.4

measuresoft scadapro 2.5

measuresoft scadapro 2.5.1

measuresoft scadapro 2.7.2

measuresoft scadapro 2.8.0

measuresoft scadapro 3.3.2

measuresoft scadapro 3.9.0

measuresoft scadapro 3.9.7

measuresoft scadapro 3.9.8

Exploits

## # $Id: scadapro_cmdexerb 13737 2011-09-16 08:23:59Z sinn3r $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' clas ...
####################################################################### Luigi Auriemma Application: Measuresoft ScadaPro wwwmeasuresoftcom/products/scada-productsaspx Versions: <= 400 Platforms: Windows Bugs: arbitrary commands execution directory traversal in ...