vendor:
                    ModbusTagServer, ScadaPhone
                by:
                    mr_me
                7.5
                        CVSS
                    HIGH
                    Buffer Overflow
                    119
                        CWE
                    Product Name: ModbusTagServer, ScadaPhone
                    Affected Version From:  
                    Affected Version To:  
                    Patch Exists: NO
                    Related CWE: 
                    CPE:  
                    Platforms Tested:  Windows XP SP3
                    2011
                    ScadaTEC ModbusTagServer & ScadaPhone (.zip) buffer overflow exploit (0day)
This exploit targets ScadaTEC ModbusTagServer and ScadaPhone software. It triggers a buffer overflow vulnerability when loading a project from a zip file. The ScadaPhone exploit bypasses DEP on Windows XP SP3, while the ModbusTagServer exploit does not. The vulnerability affects ScadaPhone versions up to 5.3.11.1230 and ModbusTagServer versions up to 4.1.1.81. The exploit has been tested on Windows XP SP3 with NX enabled.
Mitigation:
					Apply the latest patch provided by the vendor. Avoid loading projects from untrusted or unknown zip files.