Release date: 2011-12-21
Updated on: 2011-12-22
Affected Systems:
7-Technologies 7-Technologies Interactive Graphical SCADA System 9.0.0.11355
7-Technologies 7-Technologies Interactive Graphical SCADA System 9.0.0.11200
7-Technologies 7-Technologies Interactive Graphical SCADA System 9.0.0.11143
7-Technologies 7-Technologies Interactive Graphical SCADA System 9.0.0.11129
7-Technologies 7-Technologies Interactive Graphical SCADA System 9
7-Technologies 7-Technologies Interactive Graphical SCADA System 8
7-Technologies 7-Technologies Interactive Graphical SCADA System 7
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51157
Cve id: CVE-2011-4537
The 7 T Interactive Graphical SCADA System is a programmable logic controller used to control and monitor industrial processes.
The 7 T Interactive Graphical SCADA System has a buffer overflow vulnerability. by sending specially crafted packets to port 12399/TCP or port 12397/TCP, attackers can exploit this vulnerability to execute arbitrary code.
<* Source: Celil Unuver
Link: http://www.us-cert.gov/control_systems/pdf/ICSA-11-355-01-7.pdf
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
7-Technologies
--------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.igss.com/