Measuresoft.ScadaPro.XF.Function.Remote.Command.Execution

description-logoDescription

This indicates an attack attempt against a remote Command Execution vulnerability in Measuresoft ScadaPro.
A vulnerability has been reported in ScadaPro that may allow an attacker to execute an arbitrary functions of a DLL on a vulnerable system. This is possible because the user input filters fail to properly sanitize the parameter value that is passed to "XF" command.

affected-products-logoAffected Products

Measuresoft ScadaPro 4.0.0 and earlier.

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)