CVE-2012-4356 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 27.4% (pctl 98)
Patch early
A public exploit exists.
Description
Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allow remote attackers to read arbitrary files via port-46824 TCP packets specifying a file-open operation with opcode 0x78 and a .. (dot dot) in a pathname, followed by a file-read operation with opcode (1) 0x96, (2) 0x97, or (3) 0x98.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
| EPSS | 27.38% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-08-19 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| sielcosistemi | winlog lite |
| sielcosistemi | winlog pro |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Sielco Sistemi Winlog 2.07.16 - Multiple Vulnerabilities | 2012-06-27 |
References
- http://aluigi.org/adv/winlog_2-adv.txt
- http://secunia.com/advisories/49395
- http://www.sielcosistemi.com/en/news/index.html?id=69
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-213-01.pdf
- http://aluigi.org/adv/winlog_2-adv.txt
- http://secunia.com/advisories/49395
- http://www.sielcosistemi.com/en/news/index.html?id=69
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-213-01.pdf
→ the Explorer · watch your stack · NVD