Vulnerability record · CVE-2010-4142 · published 2 November 2010
CVE-2010-4142: DATAC RealWin stack buffer overflow via SCPC packets
Realflex · Realwin
DATAC RealWin 2.0 Build 6.1.8.10 and earlier contain multiple stack-based buffer overflows reachable through long SCPC_INITIALIZE, SCPC_INITIALIZE_RF, or SCPC_TXTEVENT packets. A remote, unauthenticated attacker can crash the service and potentially execute arbitrary code, making this a full-impact flaw in an industrial control product.
Description
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) SCPC_INITIALIZE, (2) SCPC_INITIALIZE_RF, or (3) SCPC_TXTEVENT packet. NOTE: it was later reported that 1.06 is also affected by one of these requests.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote unauthenticated code execution with public exploits and very high EPSS, but no confirmed KEV activity or ransomware use.
What it is
DATAC RealWin 2.0 Build 6.1.8.10 and earlier contain multiple stack-based buffer overflows reachable through long SCPC_INITIALIZE, SCPC_INITIALIZE_RF, or SCPC_TXTEVENT packets. A remote, unauthenticated attacker can crash the service and potentially execute arbitrary code, making this a full-impact flaw in an industrial control product.
Impact
An attacker gains the ability to crash the RealWin service and possibly execute arbitrary code with the privileges of the process, which on an ICS host can mean full control of the system.
Attack surface
The flaw is reached over the network via crafted SCPC packets sent to the RealWin service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Public exploit code exists in Exploit-DB and other references, and EPSS is 0.62988 (99th percentile), though the CVE is not listed in CISA KEV.
What to do
- Apply the vendor fix or upgrade RealWin past Build 6.1.8.10; if no patch is available, isolate affected hosts.
- Block or restrict network access to the RealWin service ports to trusted hosts only.
- Place RealWin systems behind a firewall or OT segmentation so SCPC traffic cannot reach them from untrusted networks.
- Monitor vendor advisories for a confirmed fixed build and validate the version in use.
- Disable or remove RealWin where it is not operationally required.
Detection
- Alert on crashes or restarts of the RealWin process and correlate with inbound SCPC traffic.
- Inspect network traffic for oversized SCPC_INITIALIZE, SCPC_INITIALIZE_RF, or SCPC_TXTEVENT packets.
- Use IDS signatures for known RealWin exploit traffic from the referenced advisories.
- Review host logs for unexpected process termination or code execution on RealWin endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://aluigi.org/adv/realwin_1-adv.txt | Exploit |
| http://secunia.com/advisories/41849 | Vendor Advisory |
| http://www.exploit-db.com/exploits/15259 | Exploit |
| http://www.exploit-db.com/exploits/15337 | Exploit |
| http://www.securityfocus.com/bid/44150 | Exploit |
| http://aluigi.org/adv/realwin_1-adv.txt | Exploit |
| http://secunia.com/advisories/41849 | Vendor Advisory |
| http://www.exploit-db.com/exploits/15259 | Exploit |
| http://www.exploit-db.com/exploits/15337 | Exploit |
| http://www.securityfocus.com/bid/44150 | Exploit |
Track CVE-2010-4142 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-4142), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.