peter bassill · operator
$ cve CVE-2011-1564 JSON

CVE-2011-1564 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 18.6% (pctl 97)

Patch early

A public exploit exists.

Description

Multiple integer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via crafted (1) On_FC_MISC_FCS_MSGBROADCAST and (2) On_FC_MISC_FCS_MSGSEND packets, which trigger a heap-based buffer overflow.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS18.63% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-189
On CISA KEVno
Public exploityes
Published2011-04-05
Last modified2026-06-16

Affected (1)

VendorProduct
realflexrealwin

Public exploits

SourceTitleDate
exploit-dbDATAC RealWin - Multiple Vulnerabilities2011-03-22

References

→ the Explorer  ·  watch your stack  ·  NVD