CVE-2011-3143: Use After Free
Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified long strings that trigger heap memory corruption.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3143?
CVE-2011-3143 is classified as a high severity vulnerability due to its potential to cause denial of service and execute arbitrary code.
How do I fix CVE-2011-3143?
To mitigate CVE-2011-3143, upgrade to at least Aveva ClearSCADA R2.3 or Schneider Electric SCX versions R4.5 and R3.9 or later.
What software is affected by CVE-2011-3143?
CVE-2011-3143 affects Aveva ClearSCADA versions 2005, 2007, and 2009, and Schneider Electric SCX versions 67 before R4.5 and 68 before R3.9.
What type of attack exploits CVE-2011-3143?
CVE-2011-3143 can be exploited through a use-after-free attack that leads to crashes or arbitrary code execution.
Can CVE-2011-3143 be exploited remotely?
Yes, CVE-2011-3143 can be exploited by remote attackers, making it a critical concern for affected systems.