7T Interactive Graphical SCADA System Malformed ODBC Packet Remote Memory Corruption Vulnerability
BID:47960
Info
7T Interactive Graphical SCADA System Malformed ODBC Packet Remote Memory Corruption Vulnerability
| Bugtraq ID: | 47960 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-2214 |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2011 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | Sebastien Renaud of VUPEN Security |
| Vulnerable: |
7-Technologies Interactive Graphical SCADA System 9.0.0.11129 7-Technologies Interactive Graphical SCADA System 9 7-Technologies Interactive Graphical SCADA System 8 7-Technologies Interactive Graphical SCADA System 0 |
| Not Vulnerable: |
7-Technologies Interactive Graphical SCADA System 9.0.0.11143 |
Discussion
7T Interactive Graphical SCADA System Malformed ODBC Packet Remote Memory Corruption Vulnerability
7T Interactive Graphical SCADA System is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code with administrative privileges. Successfully exploiting this issue will completely compromise an affected computer. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Interactive Graphical SCADA System 9.0.0.11143 are vulnerable.
7T Interactive Graphical SCADA System is prone to a remote memory-corruption vulnerability.
An attacker can exploit this issue to execute arbitrary code with administrative privileges. Successfully exploiting this issue will completely compromise an affected computer. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Interactive Graphical SCADA System 9.0.0.11143 are vulnerable.
Exploit / POC
7T Interactive Graphical SCADA System Malformed ODBC Packet Remote Memory Corruption Vulnerability
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
7T Interactive Graphical SCADA System Malformed ODBC Packet Remote Memory Corruption Vulnerability
Solution:
An update is available. Please contact the vendor for more information.
Solution:
An update is available. Please contact the vendor for more information.
References
7T Interactive Graphical SCADA System Malformed ODBC Packet Remote Memory Corruption Vulnerability
References:
References:
- IGSS - Interactive Graphical SCADA System Homepage (7-Technologies)
- VUPEN Security Research - 7T Interactive Graphical SCADA System (IGSS) Remote Me ("VUPEN Security Research"
)