PT-2012-1911 · Scadatec+1 · Scadaphone+2

Published

2012-04-03

·

Updated

2012-04-03

·

CVE-2011-4535

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TurboPower Abbrevia versions prior to 4.0 ScadaTEC ScadaPhone versions 5.3.11.1230 and earlier ScadaTEC ModbusTagServer versions 4.1.1.81 and earlier
Description The issue allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted ZIP file. This is due to a buffer overflow in the affected software.
Recommendations For TurboPower Abbrevia versions prior to 4.0, update to version 4.0 or later. For ScadaTEC ScadaPhone versions 5.3.11.1230 and earlier, update to a version later than 5.3.11.1230. For ScadaTEC ModbusTagServer versions 4.1.1.81 and earlier, update to a version later than 4.1.1.81.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4535

Affected Products

Modbustagserver
Scadaphone
Turbopower Abbrevia