V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2011-1568
CVE
CriticalConfirmedExploit available

Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in…

CVSS
10.0
Critical
EPSS
0.19
p97
Published
2011-01-01
Updated
2011-01-01
Description

Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated using the RMS Reports Delete command, related to the logging of messages to GSST.LOG. NOTE: some of these details are obtained from third party information.

Tags · CWE
CWE-134
CAPEC-67
CAPEC-135
Affected products
Igss
CVSS vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Timeline
2011-01-01
Published
2011-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.194 · p97
Known exploited (KEV)
No
Known exploits — Сканер-ВС
17024
exploitdb · https://www.exploit-db.com/exploits/17024
Enterprise
Affected products
ProductVendorStatus
igss*Tracked
Source databases
CVE