CVE-2015-0980: Scadaengine Bacnet Opc Server

High severity, CVSS 9.0. EPSS: 3.6% chance of exploitation in the next 30 days.

Format string vulnerability in BACnOPCServer.exe in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to execute arbitrary code via format string specifiers in a request.

Affected products

  • Scadaengine Bacnet Opc Server: up to and including 2.1.359.22

Published 2015-03-14. Last modified 2026-06-17.