CVE-2011-5124

Blue Coat ProxyOne and ProxySG - Stack-Based Buffer Overflow via Large Packet to Synchronization Port

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2011-5124. PoCs published by Metasploit, Paul Harrington, Travis Warren, sinn3r, including Metasploit module exploits/windows/misc/bcaaa_bof.

AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in Blue Coat Authentication and Authorization Agent (BCAAA) 5.4.6.1.54128 via port 16102, using a ROP chain to bypass DEP/ASLR and achieve remote code execution.

Description

Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 and ProxyOne, allows remote attackers to execute arbitrary code via a large packet to the synchronization port (16102/tcp).

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/17513

This Metasploit module exploits a stack buffer overflow in Blue Coat Authentication and Authorization Agent (BCAAA) 5.4.6.1.54128 via port 16102, using a ROP chain to bypass DEP/ASLR and achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Blue Coat Authentication and Authorization Agent (BCAAA) 5.4.6.1.54128
No auth needed
Prerequisites: Network access to port 16102 on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GOOD
by Paul Harrington, Travis Warren, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/bcaaa_bof.rb

This Metasploit module exploits a stack buffer overflow in Blue Coat Authentication and Authorization Agent (BCAAA) 5 via port 16102. It uses a ROP chain to bypass DEP/ASLR and achieve remote code execution, with multiple attempts for reliability.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Blue Coat Authentication and Authorization Agent (BCAAA) 5.4.6.1.54128
No auth needed
Prerequisites: Network access to port 16102 on the target system
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References
Various Sources x_refsource_confirm
https://kb.bluecoat.com/index?page=content&id=SA55

Scores

EPSS 0.7025
EPSS Percentile 98.7%

Details

CWE
CWE-119
Status published
Products (13)
bluecoat/proxyone
bluecoat/proxysg 4.2.6
bluecoat/proxysg 4.3.2.3
bluecoat/proxysg 5.1
bluecoat/proxysg 5.1.6.1
bluecoat/proxysg 5.2
bluecoat/proxysg 5.2.2.4
bluecoat/proxysg 5.2.5.2
bluecoat/proxysg 5.3
bluecoat/proxysg 5.3.2.1
... and 3 more
Published Aug 26, 2012
Tracked Since Feb 18, 2026