CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
Percentile
93.1%
Added: 11/28/2011
CVE: CVE-2011-3490
BID: 49613
OSVDB: 75490
ScadaPro is Real Time Data Acquisition software for Microsoft Windows.
ScadaPro version 4.0.0 and prior runs a legacy network service on UDP port 11234. This service contains multiple stack overflow and remote command execution vulnerabilities.
Measuresoft released ScadaPro 4.0.1 which removes the vulnerable legacy service.
<http://us-cert.gov/control_systems/pdf/ICS-ALERT-11-256-04.pdf>
<http://aluigi.altervista.org/adv/scadapro_1-adv.txt>
<http://www.measuresoft.net/news/post/Reports-of-Measuresoft-ScadaPro-400-Vulnerability-when-Windows-Firewall-is-switched-Off.aspx>
This exploit has been tested against Measuresoft ScadaPro 3.9.15 on Windows Server 2003 SP3 English (DEP OptOut) and Windows Server 2008 SP2 English (DEP OptOut).
Windows