[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96125

 
 

909

 
 

78020

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2011-1568

Date: (C)2011-04-05   (M)2017-02-03
 
CVSS Score: 10.0Access Vector: NETWORK
Exploitability Subscore: 10.0Access Complexity: LOW
Impact Subscore: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE











Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated using the RMS Reports Delete command, related to the logging of messages to GSST.LOG. NOTE: some of these details are obtained from third party information.

Reference:
EXPLOIT-DB-17024
SECUNIA-43849
BID-46936
SREASON-8182
ADV-2011-0741
http://aluigi.org/adv/igss_6-adv.txt
http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-080-03.pdf

CPE    1
cpe:/a:7t:igss
CWE    1
CWE-134

© 2013 SecPod Technologies