CVE-2012-4355: Sielcosistemi Winlog Lite

High severity, CVSS 9.3. EPSS: 8.2% chance of exploitation in the next 30 days.

TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute arbitrary code via a port-46824 TCP packet with a crafted negative integer after the opcode, triggering incorrect function-pointer processing that can lead to a buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4354.

Affected products

  • Sielcosistemi Winlog Lite: up to and including 2.07.17; version 2.06.00 only; version 2.06.03 only; version 2.06.04 only; version 2.06.06 only; version 2.06.09 only; …
  • Sielcosistemi Winlog Pro: up to and including 2.07.17; version 2.06.00 only; version 2.06.03 only; version 2.06.04 only; version 2.06.06 only; version 2.06.09 only; …

Published 2012-08-19. Last modified 2026-06-16.