PT-2012-5350 · Sielco Sistemi · Winlog Pro Scada+1

Luigi Auriemma

·

Published

2012-08-19

·

Updated

2012-08-20

·

CVE-2012-4353

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sielco Sistemi Winlog Pro SCADA versions prior to 2.07.17 Sielco Sistemi Winlog Lite SCADA versions prior to 2.07.17
Description A stack-based buffer overflow issue exists, allowing remote attackers to execute arbitrary code via a crafted TCP packet on port 46824. This occurs due to an incorrect file-open attempt triggered by the TCPIPS BinOpenFileFP function.
Recommendations For Sielco Sistemi Winlog Pro SCADA versions prior to 2.07.17, update to version 2.07.17 or later. For Sielco Sistemi Winlog Lite SCADA versions prior to 2.07.17, update to version 2.07.17 or later.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4353

Affected Products

Winlog Lite Scada
Winlog Pro Scada