CVE-2011-1564 Information
Feb 14, 2021
cve
Description
Multiple integer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via crafted (1) On_FC_MISC_FCS_MSGBROADCAST and (2) On_FC_MISC_FCS_MSGSEND packets which trigger a heap-based buffer overflow.
Reference
http://aluigi.org/adv/realwin_6-adv.txt http://secunia.com/advisories/43848 http://securityreason.com/securityalert/8177 http://www.exploit-db.com/exploits/17025 http://www.securityfocus.com/bid/46937 http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-080-04.pdf http://www.vupen.com/english/advisories/2011/0742
Share on: