CVE-2011-3497 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 57.1% (pctl 99)
Patch early
A public exploit exists.
Description
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 57.11% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-09-16 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| measuresoft | scadapro |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Measuresoft ScadaPro 4.0.0 - Multiple Vulnerabilities | 2011-09-14 |
References
- http://aluigi.altervista.org/adv/scadapro_1-adv.txt
- http://securityreason.com/securityalert/8382
- http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-256-04.pdf
- http://aluigi.altervista.org/adv/scadapro_1-adv.txt
- http://securityreason.com/securityalert/8382
- http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-256-04.pdf
→ the Explorer · watch your stack · NVD