Vulnerability record · CVE-2011-1564 · published 5 April 2011
CVE-2011-1564: Realflex realwin vulnerability
Realflex · Realwin
Multiple integer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via crafted (1) On_FC_MISC_FCS_MSGBROADCAST and (2) On_FC_MISC_FCS_MSGSEND packets, which trigger a heap-based buffer overflow.
Description
Multiple integer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier allow remote attackers to execute arbitrary code via crafted (1) On_FC_MISC_FCS_MSGBROADCAST and (2) On_FC_MISC_FCS_MSGSEND packets, which trigger a heap-based buffer overflow.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://aluigi.org/adv/realwin_6-adv.txt | Exploit |
| http://secunia.com/advisories/43848 | Vendor Advisory |
| http://securityreason.com/securityalert/8177 | |
| http://www.exploit-db.com/exploits/17025 | Exploit |
| http://www.securityfocus.com/bid/46937 | Exploit |
| http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-080-04.pdf | US Government Resource |
| http://www.vupen.com/english/advisories/2011/0742 | Vendor Advisory |
| http://aluigi.org/adv/realwin_6-adv.txt | Exploit |
| http://secunia.com/advisories/43848 | Vendor Advisory |
| http://securityreason.com/securityalert/8177 | |
| http://www.exploit-db.com/exploits/17025 | Exploit |
| http://www.securityfocus.com/bid/46937 | Exploit |
| http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-080-04.pdf | US Government Resource |
| http://www.vupen.com/english/advisories/2011/0742 | Vendor Advisory |
Track CVE-2011-1564 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-1564), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.