CVE-2012-4355
Sielcosistemi Winlog Pro < 2.07.17 - Numeric Error
Title source: ruleDescription
TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute arbitrary code via a port-46824 TCP packet with a crafted negative integer after the opcode, triggering incorrect function-pointer processing that can lead to a buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4354.
Exploits (1)
Scores
EPSS
0.3075
EPSS Percentile
96.6%
Classification
CWE
CWE-189
Status
draft
Affected Products (50)
sielcosistemi/winlog_pro
< 2.07.17
sielcosistemi/winlog_pro
sielcosistemi/winlog_pro
sielcosistemi/winlog_pro
sielcosistemi/winlog_pro
sielcosistemi/winlog_pro
sielcosistemi/winlog_pro
sielcosistemi/winlog_pro
sielcosistemi/winlog_pro
sielcosistemi/winlog_pro
sielcosistemi/winlog_pro
sielcosistemi/winlog_pro
sielcosistemi/winlog_pro
sielcosistemi/winlog_pro
sielcosistemi/winlog_pro
... and 35 more
Timeline
Published
Aug 19, 2012
Tracked Since
Feb 18, 2026