CVE-2012-4357 Information

Description

Array index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow remote attackers to execute arbitrary code by referencing within a port-46824 TCP packet an invalid file-pointer index that leads to execution of an EnterCriticalSection code block.

Reference

http://aluigi.org/adv/winlog_2-adv.txt http://secunia.com/advisories/49395 http://www.sielcosistemi.com/en/news/index.html?id=69 http://www.us-cert.gov/control_systems/pdf/ICSA-12-213-01.pdf

Share on: