Vulnerability record · CVE-2011-3497 · published 16 September 2011
CVE-2011-3497: Measuresoft ScadaPro service.exe remote arbitrary DLL function execution
Measuresoft · Scadapro
The service.exe component in Measuresoft ScadaPro 4.0.0 and earlier exposes an XF function that lets remote attackers invoke arbitrary DLL functions, described as possibly an insecure exposed method. Because the service is reachable over the network with no authentication, it gives an unauthenticated attacker a direct path to code execution on a SCADA host.
Description
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution in a SCADA product with a 10.0 CVSS score and public exploit material makes this a critical exposure for any internet- or flat-network-reachable deployment.
What it is
The service.exe component in Measuresoft ScadaPro 4.0.0 and earlier exposes an XF function that lets remote attackers invoke arbitrary DLL functions, described as possibly an insecure exposed method. Because the service is reachable over the network with no authentication, it gives an unauthenticated attacker a direct path to code execution on a SCADA host.
Impact
An attacker can execute arbitrary DLL functions on the affected system, which in a SCADA deployment can mean full control of the host and the process control environment it manages.
Attack surface
Reached over the network via the exposed XF function in service.exe; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
No CISA KEV listing and no ransomware association; EPSS is 0.57105 (99th percentile), and references include an exploit write-up, so public exploit material exists though active exploitation is not confirmed by this record.
What to do
- Apply the vendor fix or upgrade beyond ScadaPro 4.0.0; if no patch is available, isolate affected hosts.
- Block network access to the service.exe XF interface at firewalls and host ACLs, allowing only trusted engineering workstations.
- Place ScadaPro systems behind a segmented control network with no direct internet or enterprise-LAN exposure.
- Monitor vendor and US-CERT ICS advisories for updated guidance on this product line.
Detection
- Alert on unexpected network connections to the ScadaPro service port from non-engineering hosts.
- Monitor service.exe for abnormal DLL load events or process behavior on SCADA hosts.
- Review host and network logs for XF function calls or unusual RPC-style traffic to the ScadaPro service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-3497 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-3497), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.