Vulnerability Note VU#222657
RealFlex RealWin HMI service buffer overflows
Overview
RealFlex RealWin 1.06 HMI service (912/tcp) contains two stack buffer overflow vulnerabilities.
Description
RealFlex RealWin is a SCADA server package for medium and small applications designed to control and monitor real-time applications. The RealWin application runs an HMI service on port 912/tcp. This service is vulnerable to two stack-based buffer overflows. One vulnerability is caused by the use of sprintf() in the SCPC_INITIALIZE() and SCPC_INITIALIZE_RF() functions. The second vulnerability is caused by the use of strcpy() in the SCPC_TXTEVENT() function. Further information is available in ICS_CERT Advisory ICSA-10-313-01 |
Impact
An attacker may be able to cause a denial of service or potentially execute arbitrary code with the privileges of the service account on to the target machine. If the service account has administrative privileges, the attacker could take complete control of a vulnerable system. |
Solution
Upgrade to RealWin 2.1.10 (2.1 Build 6.1.10.10). |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| RealFlex Technologies Ltd. | Affected | 29 Oct 2010 | 12 Nov 2010 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.us-cert.gov/control_systems/pdf/ICSA-10-313-01.pdf
- http://aluigi.altervista.org/adv/realwin_1-adv.txt
- http://www.exploit-db.com/exploits/15337/
- http://www.realflex.com/products/realwin/realwin.php
- http://cs.realflex.com/cs/index.ssp
- https://www.metasploit.com/redmine/projects/framework/repository/revisions/11067/entry/modules/exploits/windows/scada/realwin_10.rb
Credit
Luigi Auriemma publicly reported this vulnerability.
This document was written by Michael Orlando.
Other Information
- CVE IDs: CVE-2010-4142
- Date Public: 27 Oct 2010
- Date First Published: 19 Nov 2010
- Date Last Updated: 23 Nov 2010
- Severity Metric: 12.07
- Document Revision: 22
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.