peter bassill · operator
$ cve CVE-2012-4356 JSON

CVE-2012-4356 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 27.4% (pctl 98)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allow remote attackers to read arbitrary files via port-46824 TCP packets specifying a file-open operation with opcode 0x78 and a .. (dot dot) in a pathname, followed by a file-read operation with opcode (1) 0x96, (2) 0x97, or (3) 0x98.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS27.38% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2012-08-19
Last modified2026-06-16

Affected (2)

VendorProduct
sielcosistemiwinlog lite
sielcosistemiwinlog pro

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD