CVE-2011-5163
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
15/09/2012
Last modified:
11/04/2025
Description
Buffer overflow in an unspecified third-party component in the Batch module for Schneider Electric CitectSCADA before 7.20 and Mitsubishi MX4 SCADA before 7.20 allows local users to execute arbitrary code via a long string in a login sequence.
Impact
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:mitsubishi-automation:mx4_scada:*:*:*:*:*:*:*:* | 7.10 (including) | |
cpe:2.3:a:schneider-electric:citectscada:*:*:*:*:*:*:*:* | 7.10 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/46779
- http://secunia.com/advisories/46786
- http://www.citect.com/citectscada-batch
- http://www.osvdb.org/76937
- http://www.securitytracker.com/id?1026306=
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-279-02.pdf
- https://my.mitsubishi-automation.com/downloads_show.php?portal_id=1&doc_type=safety&scat=2&sstr=MX4%2CSCADA
- http://secunia.com/advisories/46779
- http://secunia.com/advisories/46786
- http://www.citect.com/citectscada-batch
- http://www.osvdb.org/76937
- http://www.securitytracker.com/id?1026306=
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-279-02.pdf
- https://my.mitsubishi-automation.com/downloads_show.php?portal_id=1&doc_type=safety&scat=2&sstr=MX4%2CSCADA