Measuresoft's vulnerability profile centers on the SCADA Pro product family, a set of industrial control and supervisory systems deployed in operational technology environments. The recurring exposure involves access-control weaknesses, improper file-path handling, stack-based buffer overflows, and information-disclosure flaws characteristic of legacy OT software, while public exploit code frequently becomes available for disclosed issues. Defenders managing industrial control networks should prioritize patching this vendor's advisories and restrict network exposure of SCADA Pro components; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Measuresoft over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3497HIGH service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method | Sep 16, 2011 | 10.0 | 78 | NO | YES |
CVE-2011-3490HIGH Multiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbi | Sep 16, 2011 | 10.0 | 64 | NO | YES |
CVE-2011-3496HIGH service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (2) OF, or (3) EF command. | Sep 16, 2011 | 10.0 | 46 | NO | YES |
CVE-2011-3495HIGH Multiple directory traversal vulnerabilities in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to read, modify, or delete arbitrary files via the (1) | Sep 16, 2011 | 10.0 | 44 | NO | YES |
CVE-2022-2895HIGH Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based buffer overflow instances while processing a specific projec | Aug 31, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-2894HIGH Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. The controls may allow seven untrusted pointer deference instances while processing a specific projec | Aug 31, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-3263HIGH The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary | Sep 23, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-2897HIGH Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation.. | Aug 31, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-2892HIGH Measuresoft ScadaPro Server (Versions prior to 6.8.0.1) uses an unmaintained ActiveX control, which may allow an out-of-bounds write condition while processing a specific project f | Aug 31, 2022 | 7.8 | 25 | NO | NO |
CVE-2012-1824HIGH Untrusted search path vulnerability in Measuresoft ScadaPro Client before 4.0.0 and ScadaPro Server before 4.0.0 allows local users to gain privileges via a Trojan horse DLL in the | May 25, 2012 | 7.2 | 22 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Measuresoft.
Media articles that mention a CVE ID that affects a product developed by Measuresoft — matched by CVE ID, not by vendor name.