PT-2022-4633 · Measuresoft · Measuresoft Scadapro Server

Andrea Micalizzi

+3

·

Published

2022-08-23

·

Updated

2022-09-02

·

CVE-2022-2894

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Measuresoft ScadaPro Server (All Versions)
Description The issue is related to the use of unmaintained ActiveX controls in Measuresoft ScadaPro Server, which may allow untrusted pointer deference instances while processing a specific project file. This could enable a remote attacker to execute arbitrary code. The exploitation of this issue is associated with the dereference of an untrusted pointer.
Recommendations For all versions, consider disabling the use of ActiveX controls until a patch or update is available to mitigate the risk of exploitation. Restrict access to specific project files that may trigger the vulnerability to minimize the risk of remote code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2022-05517
CVE-2022-2894
ZDI-22-1134
ZDI-22-1135
ZDI-22-1136
ZDI-22-1137
ZDI-22-1138
ZDI-22-1139
ZDI-22-1140

Affected Products

Measuresoft Scadapro Server