VYPR
Unrated severityNVD Advisory· Published Aug 16, 2011· Updated Apr 29, 2026

CVE-2011-3143

CVE-2011-3143

Description

Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified long strings that trigger heap memory corruption.

Affected products

5
  • Aveva/Clearscada3 versions
    cpe:2.3:a:aveva:clearscada:2005:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:aveva:clearscada:2005:*:*:*:*:*:*:*
    • cpe:2.3:a:aveva:clearscada:2007:*:*:*:*:*:*:*
    • cpe:2.3:a:aveva:clearscada:2009:*:*:*:*:*:*:*
  • cpe:2.3:a:schneider-electric:scx_67:*:*:*:*:*:*:*:*
    Range: <r4.5
  • cpe:2.3:a:schneider-electric:scx_68:*:*:*:*:*:*:*:*
    Range: <r3.9

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.