CVE-2012-4359
Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 do not validate the return value of the realloc function, which allows remote attackers to cause a denial of service (invalid 0x00 write operation and daemon crash) or…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 do not validate the return value of the realloc function, which allows remote attackers to cause a denial of service (invalid 0x00 write operation and daemon crash) or possibly have unspecified other impact via a port-46824 TCP packet with a crafted negative integer after the opcode. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4358.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 2.52% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- sielcosistemi/winlog pro · sielcosistemi/winlog lite
- Source
- cve@mitre.org
References
- http://aluigi.org/adv/winlog_2-adv.txtExploit
- http://secunia.com/advisories/49395Vendor Advisory
- http://www.sielcosistemi.com/en/news/index.html?id=70
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-213-01.pdfUS Government Resource
- http://aluigi.org/adv/winlog_2-adv.txtExploit
- http://secunia.com/advisories/49395Vendor Advisory
- http://www.sielcosistemi.com/en/news/index.html?id=70
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-213-01.pdfUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.