TCPUploader module listens on Port 10651/TCP for incoming connections.
Exploitation of this vulnerability could allow a remote unauthenticated
user access to release OS version information. While this is a minor
vulnerability, it represents a method for further network
reconnaissance.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-0809 TCPUploader module listens on Port 10651/TCP for incoming connections. Exploitation of this vulnerability could allow a remote unauthenticated user access to release OS version information. While this is a minor vulnerability, it represents a method for further network reconnaissance.
Fixes

Solution

Progea has updated and fixed the vulnerability in Movicon Version 11.4.1150. This is available as a download from the Progea Technical Support site:  http://www.progea.com/it-it/downloads/software.aspx  . Users will be required to register on the Progea web site to download this new version.


Workaround

No workaround given by the vendor.

History

Wed, 24 Sep 2025 21:30:00 +0000

Type Values Removed Values Added
Description The TCPUploader module in Progea Movicon 11.4 before 11.4.1150 allows remote attackers to obtain potentially sensitive version information via network traffic to TCP port 10651. TCPUploader module listens on Port 10651/TCP for incoming connections. Exploitation of this vulnerability could allow a remote unauthenticated user access to release OS version information. While this is a minor vulnerability, it represents a method for further network reconnaissance.
Title Progea Movicon SCADA Exposure of Sensitive Information to an Unauthorized Actor
References
Metrics cvssV2_0

{'score': 5.0, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N'}

cvssV2_0

{'score': 4.3, 'vector': 'AV:N/AC:M/Au:N/C:P/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-09-24T21:24:10.830Z

Reserved: 2014-01-02T00:00:00

Link: CVE-2014-0778

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-04-19T19:55:07.200

Modified: 2025-09-24T22:15:34.967

Link: CVE-2014-0778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.