[Forgot Password]
Login  Register Subscribe

23631

 
 

125232

 
 

98250

 
 

909

 
 

79281

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2011-3322

Date: (C)2011-09-15   (M)2017-08-29 


Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password to the Telnet (TCP/23) port, which triggers an out-of-bounds read or write, leading to a stack-based buffer overflow.

CVSS Score: 10.0Access Vector: NETWORK
Exploit Score: 10.0Access Complexity: LOW
Impact Score: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE





Reference:
EXPLOIT-DB-17827
SECUNIA-45866
BID-49480
OSVDB-75371
SREASON-8374
http://www.stratsec.net/Research/Advisories/Procyon-Core-Server-HMI-Remote-Stack-Overflow
http://www.uscert.gov/control_systems/pdf/ICSA-11-216-01.pdf
procyon-telnet-bo(69632)

CWE    1
CWE-119

© 2013 SecPod Technologies