The SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to bypass authentication and read or write to arbitrary database fields via unspecified vectors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Bacnet_opc_server | Scadaengine | * | 2.1.359.22 (including) |