peter bassill · operator
$ cve CVE-2011-1565 JSON

CVE-2011-1565 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 64.1% (pctl 99)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to (1) read (opcode 0x3) or (2) create or write (opcode 0x2) arbitrary files via ..\ (dot dot backslash) sequences to TCP port 12401.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS64.06% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2011-04-05
Last modified2026-06-16

Affected (1)

VendorProduct
7tigss

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD