Lucene search

K
cveCertccCVE-2011-3322
HistorySep 15, 2011 - 5:58 p.m.

CVE-2011-3322

2011-09-1517:58:42
CWE-119
certcc
web.nvd.nist.gov
112
cve-2011-3322
core server
hmi service
scadatec limited
procyon scada
denial of service
remote attack
telnet
buffer overflow

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

High

EPSS

0.947

Percentile

99.3%

Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password to the Telnet (TCP/23) port, which triggers an out-of-bounds read or write, leading to a stack-based buffer overflow.

Affected configurations

Nvd
Node
scadatecprocyon_scadaMatch1.06
OR
scadatecprocyon_scadaMatch1.13
VendorProductVersionCPE
scadatecprocyon_scada1.06cpe:2.3:a:scadatec:procyon_scada:1.06:*:*:*:*:*:*:*
scadatecprocyon_scada1.13cpe:2.3:a:scadatec:procyon_scada:1.13:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

High

EPSS

0.947

Percentile

99.3%