Vulnerability record · CVE-2011-3322 · published 15 September 2011
CVE-2011-3322: Procyon SCADA Core Server HMI Telnet stack buffer overflow
Scadatec · Procyon Scada
The Core Server HMI Service (Coreservice.exe) in Scadatec Procyon SCADA 1.06 and versions before 1.14 mishandles a long password sent to its Telnet port (TCP/23), causing an out-of-bounds read or write that overflows a stack buffer. The flaw is remotely reachable without authentication and can crash the service or potentially allow code execution on a SCADA host.
Description
Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password to the Telnet (TCP/23) port, which triggers an out-of-bounds read or write, leading to a stack-based buffer overflow.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityUnauthenticated remote stack overflow in an internet-exposed SCADA service with a public exploit and very high EPSS, though no confirmed in-the-wild exploitation is recorded.
What it is
The Core Server HMI Service (Coreservice.exe) in Scadatec Procyon SCADA 1.06 and versions before 1.14 mishandles a long password sent to its Telnet port (TCP/23), causing an out-of-bounds read or write that overflows a stack buffer. The flaw is remotely reachable without authentication and can crash the service or potentially allow code execution on a SCADA host.
Impact
An unauthenticated remote attacker can crash the HMI service, disrupting SCADA operations, and may be able to execute arbitrary code in the service context.
Attack surface
Reached over the network via the Telnet service on TCP/23 by sending an oversized password; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication or user interaction is required.
Exploitation
Not listed in CISA KEV, but a public Exploit-DB entry exists and EPSS is high (0.64653, 99.2nd percentile), indicating elevated likelihood of exploitation attempts.
What to do
- Upgrade Procyon SCADA to version 1.14 or later, which the advisory indicates fixes the issue.
- Disable or block the Telnet service (TCP/23) on the Core Server HMI host if it is not operationally required.
- Restrict network access to TCP/23 to trusted management hosts via firewall or ACL rules.
- Monitor vendor and ICS-CERT advisories for updated guidance on this legacy product.
Detection
- Alert on Telnet (TCP/23) connections to Procyon Core Server HMI hosts, especially from untrusted networks.
- Inspect Telnet authentication traffic for abnormally long password fields or oversized payloads.
- Monitor Coreservice.exe for crash events or unexpected restarts on SCADA hosts.
- Watch for post-crash process creation or anomalous child processes from the HMI service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-3322 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-3322), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.