Vulnerabilities > Scadatec

DATE CVE VULNERABILITY TITLE RISK
2012-04-03 CVE-2011-4535 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earlier, and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP file.
6.8
2011-09-15 CVE-2011-3322 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Scadatec Procyon Scada 1.06/1.13
Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password to the Telnet (TCP/23) port, which triggers an out-of-bounds read or write, leading to a stack-based buffer overflow.
network
low complexity
scadatec CWE-119
critical
10.0