Vulnerability record · CVE-2011-1566 · published 5 April 2011
CVE-2011-1566: IGSS dc.exe directory traversal allows remote code execution
77t · Igss
The dc.exe component of 7-Technologies IGSS (version 9.00.00.11059 and earlier) is vulnerable to directory traversal via ..\ sequences embedded in opcodes 0xa and 0x17 sent to TCP port 12397. A remote attacker can use the traversal to place and execute arbitrary programs, giving full control of the SCADA host. The flaw is remotely reachable without authentication and carries a CVSS v2 score of 10.
Description
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allows remote attackers to execute arbitrary programs via ..\ (dot dot backslash) sequences in opcodes (1) 0xa and (2) 0x17 to TCP port 12397.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution in an industrial control system with public exploit code and very high EPSS probability.
What it is
The dc.exe component of 7-Technologies IGSS (version 9.00.00.11059 and earlier) is vulnerable to directory traversal via ..\ sequences embedded in opcodes 0xa and 0x17 sent to TCP port 12397. A remote attacker can use the traversal to place and execute arbitrary programs, giving full control of the SCADA host. The flaw is remotely reachable without authentication and carries a CVSS v2 score of 10.
Impact
An attacker gains arbitrary code execution on the IGSS server, which typically runs with high privileges in an industrial control environment, enabling full compromise of the host and potential disruption of connected control processes.
Attack surface
Reachable over the network by sending crafted opcodes to TCP port 12397; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Public exploit code exists (Exploit-DB 17024 and SecurityFocus BID 46936) and EPSS is 0.66982 (99.26th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.
What to do
- Apply the vendor fix for IGSS dc.exe; if no patch is available for the deployed version, upgrade to a supported release.
- Block or restrict TCP port 12397 at network boundaries and segment IGSS hosts from untrusted networks.
- Place IGSS systems behind a firewall with strict allowlists for control-system traffic only.
- Monitor and restrict outbound traffic from IGSS hosts to limit post-exploitation movement.
- Review US-CERT ICS-ALERT-11-080-03 and vendor advisories for additional compensating controls.
Detection
- Monitor network traffic to TCP port 12397 for opcodes 0xa and 0x17 containing ..\ sequences.
- Alert on unexpected process creation or file writes by dc.exe on IGSS hosts.
- Baseline and audit files written to IGSS installation directories for anomalous executables.
- Use IDS/IPS signatures for known IGSS dc.exe exploit traffic and review logs for repeated connection attempts to port 12397.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://aluigi.org/adv/igss_8-adv.txt | |
| http://secunia.com/advisories/43849 | Vendor Advisory |
| http://www.exploit-db.com/exploits/17024 | Exploit |
| http://www.securityfocus.com/bid/46936 | Exploit |
| http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-080-03.pdf | US Government Resource |
| http://www.vupen.com/english/advisories/2011/0741 | Vendor Advisory |
| http://aluigi.org/adv/igss_8-adv.txt | |
| http://secunia.com/advisories/43849 | Vendor Advisory |
| http://www.exploit-db.com/exploits/17024 | Exploit |
| http://www.securityfocus.com/bid/46936 | Exploit |
| http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-080-03.pdf | US Government Resource |
| http://www.vupen.com/english/advisories/2011/0741 | Vendor Advisory |
Track CVE-2011-1566 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-1566), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.