← Vulnerability feed

Vulnerability record · CVE-2011-3497 · published 16 September 2011

CVE-2011-3497: Measuresoft ScadaPro service.exe remote arbitrary DLL function execution

Measuresoft · Scadapro

The service.exe component in Measuresoft ScadaPro 4.0.0 and earlier exposes an XF function that lets remote attackers invoke arbitrary DLL functions, described as possibly an insecure exposed method. Because the service is reachable over the network with no authentication, it gives an unauthenticated attacker a direct path to code execution on a SCADA host.

10.0 CVSS 2.0 High EPSS 57% · top 1.0% CWE-200 · Information exposure
10.0CVSS 2.0 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityUnauthenticated remote code execution in a SCADA product with a 10.0 CVSS score and public exploit material makes this a critical exposure for any internet- or flat-network-reachable deployment.

What it is

The service.exe component in Measuresoft ScadaPro 4.0.0 and earlier exposes an XF function that lets remote attackers invoke arbitrary DLL functions, described as possibly an insecure exposed method. Because the service is reachable over the network with no authentication, it gives an unauthenticated attacker a direct path to code execution on a SCADA host.

Impact

An attacker can execute arbitrary DLL functions on the affected system, which in a SCADA deployment can mean full control of the host and the process control environment it manages.

Attack surface

Reached over the network via the exposed XF function in service.exe; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

No CISA KEV listing and no ransomware association; EPSS is 0.57105 (99th percentile), and references include an exploit write-up, so public exploit material exists though active exploitation is not confirmed by this record.

What to do

  • Apply the vendor fix or upgrade beyond ScadaPro 4.0.0; if no patch is available, isolate affected hosts.
  • Block network access to the service.exe XF interface at firewalls and host ACLs, allowing only trusted engineering workstations.
  • Place ScadaPro systems behind a segmented control network with no direct internet or enterprise-LAN exposure.
  • Monitor vendor and US-CERT ICS advisories for updated guidance on this product line.

Detection

  • Alert on unexpected network connections to the ScadaPro service port from non-engineering hosts.
  • Monitor service.exe for abnormal DLL load events or process behavior on SCADA hosts.
  • Review host and network logs for XF function calls or unusual RPC-style traffic to the ScadaPro service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-3497 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-3495Measuresoft scadapro path traversal vulnerabilityMultiple directory traversal vulnerabilities in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to read, modify, or dele…EPSS 10%10.0CVE-2011-3496Measuresoft scadapro improper input validation vulnerabilityservice.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (…EPSS 14%10.0CVE-2011-3490Measuresoft scadapro memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to cause a denial of service (c…EPSS 36%5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed7.5CVE-2026-20133Cisco Catalyst SD-WAN Manager insufficient file system restrictions expose dataCisco Catalyst SD-WAN Software has insufficient file system restrictions that let an attacker read sensitive files on the underlying operating system…KEVEPSS 32%analysed7.5CVE-2025-31125Vite dev server improper access control exposes arbitrary filesVite's dev server fails to restrict file access when a request uses the ?inline&import or ?raw?import query patterns, allowing content of files that …KEVEPSS 65%analysed5.5CVE-2026-20805Windows Desktop Window Manager information disclosureDesktop Windows Manager (DWM) in Microsoft Windows exposes sensitive information to an unauthorized actor, allowing a local attacker with existing ac…KEVEPSS 7.2%analysed7.5CVE-2021-41277Metabase custom GeoJSON map feature allows local file inclusionMetabase does not validate URLs supplied through the custom GeoJSON map setting (admin->settings->maps->custom maps->add a map) before loading them. …KEVEPSS 97%analysed

Source: NIST National Vulnerability Database (record CVE-2011-3497), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.