← Vulnerability feed

Vulnerability record · CVE-2011-1567 · published 5 April 2011

CVE-2011-1567: IGSS IGSSdataServer.exe stack buffer overflow via crafted opcodes

77t · Igss

IGSSdataServer.exe in 7-Technologies IGSS 9.00.00.11063 and earlier contains multiple stack-based buffer overflows reachable through crafted commands in several opcodes (0xd, 0x7, 0x8) sent to TCP port 12401. Successful exploitation can crash the service and potentially allow arbitrary code execution on the SCADA server.

10.0 CVSS 2.0 High EPSS 70% · top 0.7% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References, 12 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted (1) ListAll, (2) Write File, (3) ReadFile, (4) Delete, (5) RenameFile, and (6) FileInfo commands in an 0xd opcode; (7) the Add, (8) ReadFile, (9) Write File, (10) Rename, (11) Delete, and (12) Add commands in an RMS report templates (0x7) opcode; and (13) 0x4 command in an STDREP request (0x8) opcode to TCP port 12401.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and public exploit code makes this a high-risk flaw for exposed IGSS systems.

What it is

IGSSdataServer.exe in 7-Technologies IGSS 9.00.00.11063 and earlier contains multiple stack-based buffer overflows reachable through crafted commands in several opcodes (0xd, 0x7, 0x8) sent to TCP port 12401. Successful exploitation can crash the service and potentially allow arbitrary code execution on the SCADA server.

Impact

A remote attacker can cause a denial of service against the IGSS data server and may be able to execute arbitrary code in the context of the service. This could disrupt or compromise industrial control operations managed by IGSS.

Attack surface

The flaw is reached over the network via TCP port 12401 by sending specially crafted command payloads; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/Au:N).

Exploitation

Public exploit references exist (Exploit-DB and multiple aluigi.org advisories), and EPSS indicates a high probability of exploitation activity, though the CVE is not listed in CISA KEV.

What to do

  • Apply the vendor patch or upgrade IGSS to a version later than 9.00.00.11063 as soon as possible.
  • Restrict network access to TCP port 12401 to only trusted hosts and segments; block it from untrusted networks.
  • Segment the IGSS server from general IT networks and enforce strict firewall rules around SCADA zones.
  • Monitor for and investigate any unexpected crashes or restarts of IGSSdataServer.exe.
  • If patching is not immediately possible, consider compensating controls such as an application-layer filter or IPS signature for the affected opcodes.

Detection

  • Monitor network traffic to TCP port 12401 for anomalous or malformed command payloads, especially those using opcodes 0xd, 0x7, and 0x8.
  • Alert on repeated crashes or service restarts of IGSSdataServer.exe.
  • Use IDS/IPS signatures for known IGSS exploit patterns and review logs for connections from unexpected source IPs.
  • Baseline normal IGSS client-server communication and flag deviations in command frequency or payload size.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-1567 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-29597t igss memory buffer overflow vulnerabilityStack-based buffer overflow in the Open Database Connectivity (ODBC) service (Odbcixv9se.exe) in 7-Technologies Interactive Graphical SCADA System (I…EPSS 6.9%10.0CVE-2011-22147t igss vulnerabilityUnspecified vulnerability in the Open Database Connectivity (ODBC) component in 7T Interactive Graphical SCADA System (IGSS) before 9.0.0.11143 allow…EPSS 4.7%10.0CVE-2011-1566IGSS dc.exe directory traversal allows remote code executionThe dc.exe component of 7-Technologies IGSS (version 9.00.00.11059 and earlier) is vulnerable to directory traversal via ..\ sequences embedded in op…EPSS 67%analysed10.0CVE-2011-15687t igss vulnerabilityFormat string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in 7-Technol…EPSS 19%10.0CVE-2011-1565IGSS SCADA Data Server Directory Traversal via TCP Port 12401IGSSdataServer.exe in 7-Technologies IGSS 9.00.00.11063 and earlier contains a directory traversal flaw (CWE-22) that lets remote attackers read, cre…EPSS 64%analysed9.3CVE-2011-40537t igss vulnerabilityUntrusted search path vulnerability in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) before 9.0.0.11291 allows local users to gain pr…EPSS 1.5%7.5CVE-2011-45377t igss memory buffer overflow vulnerabilityMultiple buffer overflows in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) 9.0.0.11355 and earlier allow remote attackers to execute …EPSS 4.5%5.0CVE-2011-40507t igss memory buffer overflow vulnerabilityBuffer overflow in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) 9.0.0.11200 allows remote attackers to cause a denial of service via…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2011-1567), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.