Vulnerability Description
Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified long strings that trigger heap memory corruption.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aveva | Clearscada | 2005 |
| Schneider-Electric | Scx 67 | < r4.5 |
| Schneider-Electric | Scx 68 | < r3.9 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/44955Third Party Advisory
- http://www.digitalbond.com/scadapedia/vulnerability-notes/heap-overflow-vulnerabBroken LinkThird Party Advisory
- http://www.osvdb.org/72989Broken Link
- http://www.securityfocus.com/bid/46312Third Party AdvisoryVDB Entry
- http://www.us-cert.gov/control_systems/pdf/ICSA-10-314-01.pdfPatchThird Party AdvisoryUS Government Resource
- http://www.us-cert.gov/control_systems/pdf/ICSA-10-314-01A.pdfPatchThird Party AdvisoryUS Government Resource
- http://secunia.com/advisories/44955Third Party Advisory
- http://www.digitalbond.com/scadapedia/vulnerability-notes/heap-overflow-vulnerabBroken LinkThird Party Advisory
- http://www.osvdb.org/72989Broken Link
- http://www.securityfocus.com/bid/46312Third Party AdvisoryVDB Entry
- http://www.us-cert.gov/control_systems/pdf/ICSA-10-314-01.pdfPatchThird Party AdvisoryUS Government Resource
- http://www.us-cert.gov/control_systems/pdf/ICSA-10-314-01A.pdfPatchThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2011-3143?
CVE-2011-3143 is a vulnerability with a CVSS score of 10.0 (HIGH). Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to cause a denial of servi...
How severe is CVE-2011-3143?
CVE-2011-3143 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-3143?
Check the references section above for vendor advisories and patch information. Affected products include: Aveva Clearscada, Schneider-Electric Scx 67, Schneider-Electric Scx 68.