CVE-2012-3815
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 44%
from disclosure to weapon0 days
Published on NVDJun 27
1st PoCJun 8
metasploitJun 4
exploitation probability
44%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 46824. NOTE: some of these details are obtained from third party information.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/19409unverifiedexploitdbwww.exploit-db.com/exploits/19025unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/bugtraq/2012-06/0009.htmlhttp://secunia.com/advisories/49395http://securitytracker.com/id?1027128https://exchange.xforce.ibmcloud.com/vulnerabilities/76060http://www.osvdb.org/82654http://www.s3cur1ty.de/m1adv2012-001http://www.securityfocus.com/bid/53811http://www.sielcosistemi.com/en/news/index.html?id=69http://www.sielcosistemi.com/en/news/index.html?id=70http://www.us-cert.gov/control_systems/pdf/ICSA-12-213-01.pdf