vendor:
RealWin
by:
Luigi Auriemma
7.5
CVSS
HIGH
Stack Overflow
121, 122
CWE
Product Name: RealWin
Affected Version From: <= 2.0 (Build 6.1.8.10)
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2010
DATAC RealWin Stack Overflow Vulnerabilities
The DATAC RealWin SCADA server package for medium/small applications is vulnerable to two stack overflow vulnerabilities. The first vulnerability occurs in the SCPC_INITIALIZE and SCPC_INITIALIZE_RF functions, where a stack-based buffer overflow is caused by the usage of sprintf(). The second vulnerability occurs in the SCPC_TXTEVENT function, where a stack-based overflow is caused by the usage of strcpy() with data supplied by the attacker.
Mitigation:
Upgrade to a version later than 2.0 (Build 6.1.8.10)