10
CVSSv2

CVE-2010-4142

Published: 02/11/2010 Updated: 04/11/2010
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and previous versions allow remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) SCPC_INITIALIZE, (2) SCPC_INITIALIZE_RF, or (3) SCPC_TXTEVENT packet. NOTE: it was later reported that 1.06 is also affected by one of these requests.

Vulnerable Product Search on Vulmon Subscribe to Product

realflex realwin 2.0

realflex realwin 1.06

Exploits

## # $Id: realwin_scpc_txteventrb 11125 2010-11-24 13:44:46Z mc $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' cl ...
# Exploit Title: RealWin SCADA System SEH Overwrite # Date: 10-27-10 # Author: Blake # Software Link: wwwrealflexcom/products/realwin/realwinphp # Version: 106 # Tested on: Windows XP SP3 running in VMware Workstation (rfx) import socket, sys if len(sysargv)!= 3: print "\n[*] Usage: %s <ip> <port>\n" % sysargv[0] ...
## # $Id: realwin_scpc_initializerb 11180 2010-11-30 20:19:18Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core ...
Source: aluigiorg/adv/realwin_1-advtxt ####################################################################### Luigi Auriemma Application: DATAC RealWin wwwdataconlinecom/software/realwinphp wwwrealflexcom Versions: <= 20 (Build 61810) Platforms: ...
## # $Id: realwin_scpc_initialize_rfrb 11180 2010-11-30 20:19:18Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/c ...