peter bassill · operator
$ cve CVE-2011-2963 JSON

CVE-2011-2963 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 7.6% (pctl 94)

Patch early

A public exploit exists.

Description

TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, delete files, execute arbitrary programs, or cause a denial of service (crash) via a crafted packet to TCP port 10651.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS7.63% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2011-07-29
Last modified2026-06-16

Affected (1)

VendorProduct
progeamovicon

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD