TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, delete files, execute arbitrary programs, or cause a denial of service (crash) via a crafted packet to TCP port 10651.
References
Link | Resource |
---|---|
http://www.us-cert.gov/control_systems/pdf/ICSA-11-056-01A.pdf | Patch US Government Resource |
http://www.exploit-db.com/exploits/17034 | Exploit |
http://www.osvdb.org/72888 | |
http://www.securityfocus.com/bid/46907 | Exploit |
http://www.us-cert.gov/control_systems/pdf/ICSA-11-056-01.pdf | Patch US Government Resource |
Configurations
Information
Published : 2011-07-29 12:55
Updated : 2011-07-31 21:00
NVD link : CVE-2011-2963
Mitre link : CVE-2011-2963
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
progea
- movicon