| |
Vulnerability CVE-2011-3495
Published: 2011-09-16 Modified: 2012-02-13
Description: |
Multiple directory traversal vulnerabilities in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to read, modify, or delete arbitrary files via the (1) RF, (2) wF, (3) UF, or (4) NF command. |
See advisories in our WLB2 database: | Topic | Author | Date |
High |
| Luigi Auriemma | 20.09.2011 |
Type:
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
10/10 |
10/10 |
10/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Complete |
Complete |
Complete |
References: |
http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-256-04.pdf
http://aluigi.altervista.org/adv/scadapro_1-adv.txt
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|