Back

MEDIUM

Progea Movicon SCADA Exposure of Sensitive Information to an Unauthorized Actor

Published Apr 19, 2014

Description

TCPUploader module listens on Port 10651/TCP for incoming connections. Exploitation of this vulnerability could allow a remote unauthenticated user access to release OS version information. While this is a minor vulnerability, it represents a method for further network reconnaissance.

Affected products

Remediation

Vendor solution

Progea has updated and fixed the vulnerability in Movicon Version 11.4.1150. This is available as a download from the Progea Technical Support site:  http://www.progea.com/it-it/downloads/software.aspx  .

Users will be required to register on the Progea web site to download this new version.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Apr 19, 2014
Updated Sep 24, 2025
Reserved Jan 2, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a