← Vulnerability feed

Vulnerability record · CVE-2011-1566 · published 5 April 2011

CVE-2011-1566: IGSS dc.exe directory traversal allows remote code execution

77t · Igss

The dc.exe component of 7-Technologies IGSS (version 9.00.00.11059 and earlier) is vulnerable to directory traversal via ..\ sequences embedded in opcodes 0xa and 0x17 sent to TCP port 12397. A remote attacker can use the traversal to place and execute arbitrary programs, giving full control of the SCADA host. The flaw is remotely reachable without authentication and carries a CVSS v2 score of 10.

10.0 CVSS 2.0 High EPSS 67% · top 0.7% CWE-22 · Path traversal
10.0CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to execute arbitrary programs via ..\ (dot dot backslash) sequences in opcodes (1) 0xa and (2) 0x17 to TCP port 12397.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution in an industrial control system with public exploit code and very high EPSS probability.

What it is

The dc.exe component of 7-Technologies IGSS (version 9.00.00.11059 and earlier) is vulnerable to directory traversal via ..\ sequences embedded in opcodes 0xa and 0x17 sent to TCP port 12397. A remote attacker can use the traversal to place and execute arbitrary programs, giving full control of the SCADA host. The flaw is remotely reachable without authentication and carries a CVSS v2 score of 10.

Impact

An attacker gains arbitrary code execution on the IGSS server, which typically runs with high privileges in an industrial control environment, enabling full compromise of the host and potential disruption of connected control processes.

Attack surface

Reachable over the network by sending crafted opcodes to TCP port 12397; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Public exploit code exists (Exploit-DB 17024 and SecurityFocus BID 46936) and EPSS is 0.66982 (99.26th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.

What to do

  • Apply the vendor fix for IGSS dc.exe; if no patch is available for the deployed version, upgrade to a supported release.
  • Block or restrict TCP port 12397 at network boundaries and segment IGSS hosts from untrusted networks.
  • Place IGSS systems behind a firewall with strict allowlists for control-system traffic only.
  • Monitor and restrict outbound traffic from IGSS hosts to limit post-exploitation movement.
  • Review US-CERT ICS-ALERT-11-080-03 and vendor advisories for additional compensating controls.

Detection

  • Monitor network traffic to TCP port 12397 for opcodes 0xa and 0x17 containing ..\ sequences.
  • Alert on unexpected process creation or file writes by dc.exe on IGSS hosts.
  • Baseline and audit files written to IGSS installation directories for anomalous executables.
  • Use IDS/IPS signatures for known IGSS dc.exe exploit traffic and review logs for repeated connection attempts to port 12397.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-1566 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-29597t igss memory buffer overflow vulnerabilityStack-based buffer overflow in the Open Database Connectivity (ODBC) service (Odbcixv9se.exe) in 7-Technologies Interactive Graphical SCADA System (I…EPSS 6.9%10.0CVE-2011-22147t igss vulnerabilityUnspecified vulnerability in the Open Database Connectivity (ODBC) component in 7T Interactive Graphical SCADA System (IGSS) before 9.0.0.11143 allow…EPSS 4.7%10.0CVE-2011-1567IGSS IGSSdataServer.exe stack buffer overflow via crafted opcodesIGSSdataServer.exe in 7-Technologies IGSS 9.00.00.11063 and earlier contains multiple stack-based buffer overflows reachable through crafted commands…EPSS 70%analysed10.0CVE-2011-15687t igss vulnerabilityFormat string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in 7-Technol…EPSS 19%10.0CVE-2011-1565IGSS SCADA Data Server Directory Traversal via TCP Port 12401IGSSdataServer.exe in 7-Technologies IGSS 9.00.00.11063 and earlier contains a directory traversal flaw (CWE-22) that lets remote attackers read, cre…EPSS 64%analysed9.3CVE-2011-40537t igss vulnerabilityUntrusted search path vulnerability in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) before 9.0.0.11291 allows local users to gain pr…EPSS 1.5%7.5CVE-2011-45377t igss memory buffer overflow vulnerabilityMultiple buffer overflows in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) 9.0.0.11355 and earlier allow remote attackers to execute …EPSS 4.5%5.0CVE-2011-40507t igss memory buffer overflow vulnerabilityBuffer overflow in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) 9.0.0.11200 allows remote attackers to cause a denial of service via…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2011-1566), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.