CVE-2011-3143

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
16/08/2011
Last modified:
11/04/2025

Description

Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified long strings that trigger heap memory corruption.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:aveva:clearscada:2005:*:*:*:*:*:*:*
cpe:2.3:a:aveva:clearscada:2007:*:*:*:*:*:*:*
cpe:2.3:a:aveva:clearscada:2009:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:scx_67:*:*:*:*:*:*:*:* r4.5 (excluding)
cpe:2.3:a:schneider-electric:scx_68:*:*:*:*:*:*:*:* r3.9 (excluding)