CVE-2011-4871

OPC Systems.NET < 4.0 - Denial of Service via Malformed .NET RPC Packet

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-4871. PoCs published by Luigi Auriemma.

AI-analyzed exploit summary This exploit demonstrates a Denial of Service (DoS) vulnerability in OPC Systems.NET by sending a malformed .NET RPC packet to freeze the OPCSystemsService.exe process with 100% CPU usage. The PoC uses a custom tool (udpsz) to craft and send the malicious packet.

Description

Open Automation Software OPC Systems.NET before 5.0 allows remote attackers to cause a denial of service via a malformed .NET RPC packet on TCP port 58723.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Luigi Auriemma · textdoswindows
https://www.exploit-db.com/exploits/17965

This exploit demonstrates a Denial of Service (DoS) vulnerability in OPC Systems.NET by sending a malformed .NET RPC packet to freeze the OPCSystemsService.exe process with 100% CPU usage. The PoC uses a custom tool (udpsz) to craft and send the malicious packet.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: OPC Systems.NET <= 4.00.0048
No auth needed
Prerequisites: Network access to the target service on port 58723
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
US Government Resource x_refsource_misc
http://www.us-cert.gov/control_systems/pdf/ICSA-12-012-01.pdf

Scores

EPSS 0.0316
EPSS Percentile 86.3%

Details

CWE
CWE-20
Status published
Products (1)
opcsystems/opcsystems.net < 4.0
Published Apr 18, 2012
Tracked Since Feb 18, 2026