CVE-2012-4358
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD
Description
Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 do not validate the return value of the realloc function, which allows remote attackers to cause a denial of service (invalid 0x00 write operation and daemon crash) or possibly have unspecified other impact via a port-46824 TCP packet with a crafted positive integer after the opcode.
Affected (54)
Products: Sielcosistemi: Winlog Pro, Winlog Lite
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.07.16 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.07.16 |
References (8)
Source: cve@mitre.org
Source: cve@mitre.org
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Timeline
No history available yet.