CVE-2011-2963 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 7.6% (pctl 94)
Patch early
A public exploit exists.
Description
TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, delete files, execute arbitrary programs, or cause a denial of service (crash) via a crafted packet to TCP port 10651.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 7.63% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-07-29 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| progea | movicon |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Progea Movicon 11 - 'TCPUploadServer' Remote File System | 2011-03-23 |
References
- http://www.exploit-db.com/exploits/17034
- http://www.osvdb.org/72888
- http://www.securityfocus.com/bid/46907
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-056-01.pdf
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-056-01A.pdf
- http://www.exploit-db.com/exploits/17034
- http://www.osvdb.org/72888
- http://www.securityfocus.com/bid/46907
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-056-01.pdf
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-056-01A.pdf
→ the Explorer · watch your stack · NVD