CVE-2011-1564: Buffer Overflow
Published Apr 5, 2011
·Updated
Multiple integer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via crafted (1) OnFCMISCFCSMSGBROADCAST and (2) OnFCMISCFCSMSGSEND packets, which trigger a heap-based buffer overflow.
Affected Software
3 affected components
RealFlex RealWin=1.06
RealFlex RealWin<=2.1
RealFlex RealWin=2.0
Event History
Apr 5, 2011
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1564?
CVE-2011-1564 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2011-1564?
To fix CVE-2011-1564, update your DATAC RealFlex RealWin software to version 2.2 or later.
3
What types of attacks can CVE-2011-1564 facilitate?
CVE-2011-1564 can facilitate remote code execution attacks through crafted packets.
4
What software versions are affected by CVE-2011-1564?
CVE-2011-1564 affects RealFlex RealWin versions up to and including 2.1.
5
Who is impacted by CVE-2011-1564?
Organizations using vulnerable versions of DATAC RealFlex RealWin are impacted by CVE-2011-1564.