CVE-2011-3322
Scadatec Procyon SCADA < 1.14 - Remote Code Execution via Long Telnet Password
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2011-3322.
PoCs published by Metasploit, including Metasploit module exploits/windows/scada/procyon_core_server.
AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in Procyon Core Server HMI <= v1.13 via coreservice.exe. It leverages an egghunter to bypass space constraints and achieves remote code execution by overwriting a structured exception handling record.
Description
Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password to the Telnet (TCP/23) port, which triggers an out-of-bounds read or write, leading to a stack-based buffer overflow.
Exploits (2)
This Metasploit module exploits a stack-based buffer overflow in Procyon Core Server HMI <= v1.13 via coreservice.exe. It leverages an egghunter to bypass space constraints and achieves remote code execution by overwriting a structured exception handling record.
This Metasploit module exploits a stack-based buffer overflow in Procyon Core Server's coreservice.exe (v1.13 or earlier) via unauthenticated password processing, allowing remote code execution by overwriting SEH records. It uses an egghunter to locate and execute the payload.