peter bassill · operator
$ cve CVE-2011-3495 JSON

CVE-2011-3495 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 10.3% (pctl 96)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to read, modify, or delete arbitrary files via the (1) RF, (2) wF, (3) UF, or (4) NF command.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS10.29% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2011-09-16
Last modified2026-06-16

Affected (1)

VendorProduct
measuresoftscadapro

Public exploits

SourceTitleDate
exploit-dbMeasuresoft ScadaPro 4.0.0 - Multiple Vulnerabilities2011-09-14

References

→ the Explorer  ·  watch your stack  ·  NVD