CVE-2012-4357 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 7.4% (pctl 94)
Patch early
A public exploit exists.
Description
Array index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow remote attackers to execute arbitrary code by referencing, within a port-46824 TCP packet, an invalid file-pointer index that leads to execution of an EnterCriticalSection code block.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 7.35% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-08-19 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| sielcosistemi | winlog lite |
| sielcosistemi | winlog pro |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Sielco Sistemi Winlog 2.07.16 - Multiple Vulnerabilities | 2012-06-27 |
References
- http://aluigi.org/adv/winlog_2-adv.txt
- http://secunia.com/advisories/49395
- http://www.sielcosistemi.com/en/news/index.html?id=69
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-213-01.pdf
- http://aluigi.org/adv/winlog_2-adv.txt
- http://secunia.com/advisories/49395
- http://www.sielcosistemi.com/en/news/index.html?id=69
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-213-01.pdf
→ the Explorer · watch your stack · NVD