CVE-2011-1564

DATAC RealFlex RealWin <2.1 Build 6.1.10.10 - RCE

Title source: llm
STIX 2.1

Description

Multiple integer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via crafted (1) On_FC_MISC_FCS_MSGBROADCAST and (2) On_FC_MISC_FCS_MSGSEND packets, which trigger a heap-based buffer overflow.

Exploits (1)

exploitdb WORKING POC
by Luigi Auriemma · textdoswindows
https://www.exploit-db.com/exploits/17025

References (7)

Core 7
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46937
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8177
Exploit x_refsource_misc
http://aluigi.org/adv/realwin_6-adv.txt
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/17025
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43848
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0742

Scores

EPSS 0.3770
EPSS Percentile 97.2%

Details

CWE
CWE-189
Status published
Products (3)
realflex/realwin 1.06
realflex/realwin 2.0
realflex/realwin < 2.1
Published Apr 05, 2011
Tracked Since Feb 18, 2026