service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://securityreason.com/securityalert/8382 | third party advisory |
http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-256-04.pdf | us government resource |
http://aluigi.altervista.org/adv/scadapro_1-adv.txt | exploit |