CVE-2023-30459

HIGH

Smartptt Scada - Remote Code Execution

Title source: rule
STIX 2.1

Description

SmartPTT SCADA 1.1.0.0 allows remote code execution (when the attacker has administrator privileges) by writing a malicious C# script and executing it on the server (via server settings in the administrator control panel on port 8101, by default).

Exploits (1)

nomisec WORKING POC 3 stars
by Toxich4 · poc
https://github.com/Toxich4/CVE-2023-30459

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://github.com/Toxich4/CVE-2023-30459

Scores

CVSS v3 7.2
EPSS 0.3360
EPSS Percentile 97.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

Status published
Products (1)
smartptt/smartptt_scada 1.1
Published Apr 14, 2023
Tracked Since Feb 18, 2026