CVE-2012-4357: Sielcosistemi Winlog Lite
High severity, CVSS 9.3. EPSS: 7.4% chance of exploitation in the next 30 days.
Array index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow remote attackers to execute arbitrary code by referencing, within a port-46824 TCP packet, an invalid file-pointer index that leads to execution of an EnterCriticalSection code block.
Affected products
- Sielcosistemi Winlog Lite: up to and including 2.07.16; version 2.06.00 only; version 2.06.03 only; version 2.06.04 only; version 2.06.06 only; version 2.06.09 only; …
- Sielcosistemi Winlog Pro: up to and including 2.07.16; version 2.06.00 only; version 2.06.03 only; version 2.06.04 only; version 2.06.06 only; version 2.06.09 only; …
Published 2012-08-19. Last modified 2026-06-16.