Vulnerability record · CVE-2011-1567 · published 5 April 2011
CVE-2011-1567: IGSS IGSSdataServer.exe stack buffer overflow via crafted opcodes
77t · Igss
IGSSdataServer.exe in 7-Technologies IGSS 9.00.00.11063 and earlier contains multiple stack-based buffer overflows reachable through crafted commands in several opcodes (0xd, 0x7, 0x8) sent to TCP port 12401. Successful exploitation can crash the service and potentially allow arbitrary code execution on the SCADA server.
Description
Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted (1) ListAll, (2) Write File, (3) ReadFile, (4) Delete, (5) RenameFile, and (6) FileInfo commands in an 0xd opcode; (7) the Add, (8) ReadFile, (9) Write File, (10) Rename, (11) Delete, and (12) Add commands in an RMS report templates (0x7) opcode; and (13) 0x4 command in an STDREP request (0x8) opcode to TCP port 12401.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and public exploit code makes this a high-risk flaw for exposed IGSS systems.
What it is
IGSSdataServer.exe in 7-Technologies IGSS 9.00.00.11063 and earlier contains multiple stack-based buffer overflows reachable through crafted commands in several opcodes (0xd, 0x7, 0x8) sent to TCP port 12401. Successful exploitation can crash the service and potentially allow arbitrary code execution on the SCADA server.
Impact
A remote attacker can cause a denial of service against the IGSS data server and may be able to execute arbitrary code in the context of the service. This could disrupt or compromise industrial control operations managed by IGSS.
Attack surface
The flaw is reached over the network via TCP port 12401 by sending specially crafted command payloads; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/Au:N).
Exploitation
Public exploit references exist (Exploit-DB and multiple aluigi.org advisories), and EPSS indicates a high probability of exploitation activity, though the CVE is not listed in CISA KEV.
What to do
- Apply the vendor patch or upgrade IGSS to a version later than 9.00.00.11063 as soon as possible.
- Restrict network access to TCP port 12401 to only trusted hosts and segments; block it from untrusted networks.
- Segment the IGSS server from general IT networks and enforce strict firewall rules around SCADA zones.
- Monitor for and investigate any unexpected crashes or restarts of IGSSdataServer.exe.
- If patching is not immediately possible, consider compensating controls such as an application-layer filter or IPS signature for the affected opcodes.
Detection
- Monitor network traffic to TCP port 12401 for anomalous or malformed command payloads, especially those using opcodes 0xd, 0x7, and 0x8.
- Alert on repeated crashes or service restarts of IGSSdataServer.exe.
- Use IDS/IPS signatures for known IGSS exploit patterns and review logs for connections from unexpected source IPs.
- Baseline normal IGSS client-server communication and flag deviations in command frequency or payload size.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-1567 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-1567), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.