CVE-2012-4354

critical
Published 2012-08-19 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
10.0

Description

TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allows remote attackers to execute arbitrary code via a port-46824 TCP packet with a crafted positive integer after the opcode, triggering incorrect function-pointer processing that can lead to a buffer overflow. NOTE: some of these details are obtained from third party information.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-19409 dos windows verified
Luigi Auriemma ยท 2012-06-27

Sielco Sistemi Winlog 2.07.16 - Multiple Vulnerabilities

Source code queued for fetch โ€” refresh in a moment.

Application impact

VendorProductVersionsFixed
sielcosistemiwinlog_pro{"endIncluding":"2.07.16"}
sielcosistemiwinlog_pro2.06.00
sielcosistemiwinlog_pro2.06.03
sielcosistemiwinlog_pro2.06.04
sielcosistemiwinlog_pro2.06.06
sielcosistemiwinlog_pro2.06.09
sielcosistemiwinlog_pro2.06.10
sielcosistemiwinlog_pro2.06.12
sielcosistemiwinlog_pro2.06.13
sielcosistemiwinlog_pro2.06.14
sielcosistemiwinlog_pro2.06.18
sielcosistemiwinlog_pro2.06.21
sielcosistemiwinlog_pro2.06.24
sielcosistemiwinlog_pro2.06.25
sielcosistemiwinlog_pro2.06.28
sielcosistemiwinlog_pro2.06.40
sielcosistemiwinlog_pro2.06.46
sielcosistemiwinlog_pro2.06.50
sielcosistemiwinlog_pro2.06.60
sielcosistemiwinlog_pro2.06.73
sielcosistemiwinlog_pro2.06.86
sielcosistemiwinlog_pro2.07.00
sielcosistemiwinlog_pro2.07.01
sielcosistemiwinlog_pro2.07.08
sielcosistemiwinlog_pro2.07.09
sielcosistemiwinlog_pro2.07.11
sielcosistemiwinlog_pro2.07.14
sielcosistemiwinlog_lite{"endIncluding":"2.07.16"}
sielcosistemiwinlog_lite2.06.00
sielcosistemiwinlog_lite2.06.03
sielcosistemiwinlog_lite2.06.04
sielcosistemiwinlog_lite2.06.06
sielcosistemiwinlog_lite2.06.09
sielcosistemiwinlog_lite2.06.10
sielcosistemiwinlog_lite2.06.12
sielcosistemiwinlog_lite2.06.13
sielcosistemiwinlog_lite2.06.14
sielcosistemiwinlog_lite2.06.18
sielcosistemiwinlog_lite2.06.21
sielcosistemiwinlog_lite2.06.24
sielcosistemiwinlog_lite2.06.25
sielcosistemiwinlog_lite2.06.28
sielcosistemiwinlog_lite2.06.40
sielcosistemiwinlog_lite2.06.46
sielcosistemiwinlog_lite2.06.50
sielcosistemiwinlog_lite2.06.60
sielcosistemiwinlog_lite2.06.73
sielcosistemiwinlog_lite2.06.86
sielcosistemiwinlog_lite2.07.00
sielcosistemiwinlog_lite2.07.01
sielcosistemiwinlog_lite2.07.08
sielcosistemiwinlog_lite2.07.09
sielcosistemiwinlog_lite2.07.11
sielcosistemiwinlog_lite2.07.14

References

CWEs

CWE-189

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.