Array index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow remote attackers to execute arbitrary code by referencing, within a port-46824 TCP packet, an invalid file-pointer index that leads to execution of an EnterCriticalSection code block.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://aluigi.org/adv/winlog_2-adv.txt | exploit |
http://www.us-cert.gov/control_systems/pdf/ICSA-12-213-01.pdf | us government resource |
http://secunia.com/advisories/49395 | third party advisory vendor advisory |
http://www.sielcosistemi.com/en/news/index.html?id=69 |