CVE-2011-5124

Bluecoat Proxyone - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 and ProxyOne, allows remote attackers to execute arbitrary code via a large packet to the synchronization port (16102/tcp).

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/17513
metasploit WORKING POC GOOD
by Paul Harrington, Travis Warren, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/bcaaa_bof.rb

Scores

EPSS 0.7025
EPSS Percentile 98.7%

Details

CWE
CWE-119
Status published
Products (13)
bluecoat/proxyone
bluecoat/proxysg 4.2.6
bluecoat/proxysg 4.3.2.3
bluecoat/proxysg 5.1
bluecoat/proxysg 5.1.6.1
bluecoat/proxysg 5.2
bluecoat/proxysg 5.2.2.4
bluecoat/proxysg 5.2.5.2
bluecoat/proxysg 5.3
bluecoat/proxysg 5.3.2.1
... and 3 more
Published Aug 26, 2012
Tracked Since Feb 18, 2026