CVE-2012-3815 describes a critical buffer overflow vulnerability in Sielco Sistemi Winlog Pro and Winlog Lite SCADA systems (versions prior to 2.07.18). This flaw allows remote unauthenticated attackers to execute arbitrary code by sending a specially crafted packet to TCP port 46824. With a CVSS score of 9.3, this vulnerability is highly severe, indicating complete compromise of confidentiality, integrity, and availability with medium attack complexity. While not listed on CISA's KEV catalog, public exploit modules exist for older versions (2.07.14-2.07.16), and despite its age and severity, it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.07.14CPE matchmatch criteria | cpe:2.3:a:sielcosistemi:winlog_lite:*:*:*:*:*:*:*:* | ||
2.06.00CPE matchmatch criteria | cpe:2.3:a:sielcosistemi:winlog_lite:2.06.00:*:*:*:*:*:*:* | ||
2.06.03CPE matchmatch criteria | cpe:2.3:a:sielcosistemi:winlog_lite:2.06.03:*:*:*:*:*:*:* | ||
2.06.04CPE matchmatch criteria | cpe:2.3:a:sielcosistemi:winlog_lite:2.06.04:*:*:*:*:*:*:* | ||
2.06.06CPE matchmatch criteria | cpe:2.3:a:sielcosistemi:winlog_lite:2.06.06:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.