""ET SCADA RealWin SCADA System Buffer Overflow""

SID: 2011976

Revision: 1

Class Type: attempted-dos

Metadata: created_at 2010_11_24, confidence High, updated_at 2010_11_24

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: 912

Flow: established,to_server

Contents:

  • Value: "|64 12 54 6a|" Depth: 4

  • Value: "|00 00 00 f4 1f 00 00|"

  • Value: !"|0a|"

Within: 7

PCRE: "/\x64\x12\x54\x6a[\x20\x10\x02]\x00\x00\x00\xf4\x1f\x00\x00/"

Special Options:

source