6.8
CVSSv2

CVE-2011-4535

Published: 03/04/2012 Updated: 03/04/2012
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in TurboPower Abbrevia prior to 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and previous versions, ScadaTEC ModbusTagServer 4.1.1.81 and previous versions, and other products, allows remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP file.

Vulnerable Product Search on Vulmon Subscribe to Product

craig peterson turbopower abbrevia

scadatec scadaphone

scadatec modbustagserver

Exploits

<?php /* ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ScadaTEC ModbusTagServer & ScadaPhone (zip) buffer overflow exploit (0day) Date: 09/09/2011 Author: mr_me (@net__ninja) Vendor: wwwscadateccom/ ScadaPhone Version: <= 53111230 ModbusTagServer Version: <= 41181 Tested on: Windows XP SP ...
## # $Id: scadaphone_ziprb 13728 2011-09-13 20:10:28Z swtornio $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' requ ...