← Vulnerability feed

Vulnerability record · CVE-2011-3143 · published 16 August 2011

CVE-2011-3143: Aveva clearscada vulnerability

Aveva · Clearscada

Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified long strings that trigger heap memory corruption.

10.0 CVSS 2.0 High EPSS 7.5% · top 5.7% CWE-399 · CWE-399
10.0CVSS 2.0 base score
7.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified long strings that trigger heap memory corruption.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-3143 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2017-6021Aveva clearscada improper input validation vulnerabilityIn Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 …EPSS 1.7%7.5CVE-2017-9962Aveva clearscada memory buffer overflow vulnerabilitySchneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed reques…EPSS 1.0%6.8CVE-2014-0779Aveva clearscada memory buffer overflow vulnerabilityThe PLC driver in ServerMain.exe in the Kepware KepServerEX 4 component in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R2 build 71.4…EPSS 1.5%6.4CVE-2014-5412Aveva clearscada improper authentication vulnerabilitySchneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access…EPSS 1.6%6.4CVE-2014-5413Aveva clearscada vulnerabilitySchneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easie…EPSS 1.0%4.9CVE-2014-5411Aveva clearscada cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote a…EPSS 1.3%4.3CVE-2013-6142Aveva clearscada vulnerabilityDNP3Driver.exe in the DNP3 driver in Schneider Electric ClearSCADA 2010 R2 through 2010 R3.1 and SCADA Expert ClearSCADA 2013 R1 through 2013 R1.2 al…EPSS 1.2%4.3CVE-2011-3144Aveva clearscada cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2011-3143), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.