Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Measuresoft

First CVE: Sep 16, 2011Active for: 15 yearsTotal CVEs: 13
63.8
VTI Score
TOP TARGET

Measuresoft's vulnerability profile centers on the SCADA Pro product family, a set of industrial control and supervisory systems deployed in operational technology environments. The recurring exposure involves access-control weaknesses, improper file-path handling, stack-based buffer overflows, and information-disclosure flaws characteristic of legacy OT software, while public exploit code frequently becomes available for disclosed issues. Defenders managing industrial control networks should prioritize patching this vendor's advisories and restrict network exposure of SCADA Pro components; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Measuresoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2011
14 years ago
Most Recent CVE
Apr 30, 2024
815 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-3497HIGH
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method
Sep 16, 201110.078NOYES
CVE-2011-3490HIGH
Multiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbi
Sep 16, 201110.064NOYES
CVE-2011-3496HIGH
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (2) OF, or (3) EF command.
Sep 16, 201110.046NOYES
CVE-2011-3495HIGH
Multiple directory traversal vulnerabilities in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to read, modify, or delete arbitrary files via the (1)
Sep 16, 201110.044NOYES
CVE-2022-2895HIGH
Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based buffer overflow instances while processing a specific projec
Aug 31, 20227.826NONO
CVE-2022-2894HIGH
Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. The controls may allow seven untrusted pointer deference instances while processing a specific projec
Aug 31, 20227.826NONO
CVE-2022-3263HIGH
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary
Sep 23, 20227.825NONO
CVE-2022-2897HIGH
Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation..
Aug 31, 20227.825NONO
CVE-2022-2892HIGH
Measuresoft ScadaPro Server (Versions prior to 6.8.0.1) uses an unmaintained ActiveX control, which may allow an out-of-bounds write condition while processing a specific project f
Aug 31, 20227.825NONO
CVE-2012-1824HIGH
Untrusted search path vulnerability in Measuresoft ScadaPro Client before 4.0.0 and ScadaPro Server before 4.0.0 allows local users to gain privileges via a Trojan horse DLL in the
May 25, 20127.222NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
92%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local8 (61.5%)
Network0 (0.0%)
Unknown5 (38.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (61.5%)
High0 (0.0%)
Unknown5 (38.5%)
User Interaction
None4 (30.8%)
Unknown5 (38.5%)
Required4 (30.8%)
Privileges Required
Low4 (30.8%)
High0 (0.0%)
None4 (30.8%)
Unknown5 (38.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
30.8% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Measuresoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Measuresoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Measuresoft's Products

View all 3 CNAs →

Top CWEs