8 results (0.006 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

23 Sep 2022 — The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges. El descriptor de seguridad de Measuresoft ScadaPro Server versión 6.7, presenta permisos inconsistentes, lo que podría permitir a un usuario local privilegiado limitado modificar la ruta binaria del servicio e iniciar comandos maliciosos con privilegios SYSTEM. This vulner... • https://www.cisa.gov/uscert/ics/advisories/icsa-22-265-01 • CWE-276: Incorrect Default Permissions CWE-284: Improper Access Control •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

23 Aug 2022 — Measuresoft ScadaPro Server (Versions prior to 6.8.0.1) uses an unmaintained ActiveX control, which may allow an out-of-bounds write condition while processing a specific project file. Measuresoft ScadaPro Server (Versiones anteriores a 6.8.0.1) usa un control ActiveX no mantenido, que puede permitir una condición de escritura fuera de límites mientras es procesado un archivo de proyecto específico This vulnerability allows remote attackers to execute arbitrary code on affected installations of Measuresoft ... • https://www.cisa.gov/uscert/ics/advisories/icsa-22-235-05 • CWE-787: Out-of-bounds Write •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

23 Aug 2022 — Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. The controls may allow seven untrusted pointer deference instances while processing a specific project file. Measuresoft ScadaPro Server (Todas las versiones) usa controles ActiveX sin mantenimiento. Los controles pueden permitir siete instancias de deferencia de puntero no confiable mientras es procesado un archivo de proyecto específico This vulnerability allows remote attackers to execute arbitrary code on affected installatio... • https://www.cisa.gov/uscert/ics/advisories/icsa-22-235-06 • CWE-822: Untrusted Pointer Dereference •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

23 Aug 2022 — Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based buffer overflow instances while processing a specific project file. Measuresoft ScadaPro Server (Todas las versiones) usa controles ActiveX no mantenidos. Estos controles pueden permitir dos instancias de desbordamiento de búfer en la región stack de la memoria mientras es procesado un archivo de proyecto específico This vulnerability allows remote attackers to execute arbitrary code on af... • https://www.cisa.gov/uscert/ics/advisories/icsa-22-235-06 • CWE-121: Stack-based Buffer Overflow •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

23 Aug 2022 — Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation.. Measuresoft ScadaPro Server y Client (Todas las versiones) no resuelven apropiadamente los enlaces antes de acceder a archivos; esto podría permitir una escalada de privilegios.. This vulnerability allows local attackers to escalate privileges on affected installations of Measuresoft ScadaPro Server. An attacker must first obtain the ability to execute low-privilege... • https://www.cisa.gov/uscert/ics/advisories/icsa-22-235-06 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

23 Aug 2022 — Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow a denial-of-service condition. Measuresoft ScadaPro Server y Client (Todas las versiones) no resuelven apropiadamente los enlaces antes de acceder a los archivos; esto podría permitir una condición de denegación de servicio This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Measuresoft ScadaPro Client. An attacker must first obta... • https://www.cisa.gov/uscert/ics/advisories/icsa-22-235-06 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

23 Aug 2022 — Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file. Measuresoft ScadaPro Server (Todas las versiones) permite un uso de memoria previamente liberada mientras que el procesamiento de un archivo de proyecto específico This vulnerability allows remote attackers to execute arbitrary code on affected installations of Measuresoft ScadaPro Server. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open ... • https://www.cisa.gov/uscert/ics/advisories/icsa-22-235-06 • CWE-121: Stack-based Buffer Overflow CWE-416: Use After Free •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

25 May 2012 — Untrusted search path vulnerability in Measuresoft ScadaPro Client before 4.0.0 and ScadaPro Server before 4.0.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory. Vulnerabilidad de búsqueda no confiable en la ruta (path) en Measuresoft ScadaPro Client anterior a v4.0.0 permite a usuarios locales ganar privilegios mediante un troyano DLL en el directorio de trabajo actual. • http://www.measuresoft.net/downloads/Measuresoft%20SCADA%204.4.6/issue_disks/Client/DOCUMENTATION/ReleaseNotes.doc •