7.6
CVSSv2

CVE-2008-2639

Published: 16/06/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 770
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote malicious users to execute arbitrary code via a long string in the second application packet in a TCP session on port 20222.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

citect citectfacilities 7

citect citectscada 6

citect citectscada 7

Exploits

This Metasploit module exploits a stack overflow in CitectSCADA's ODBC daemon This has only been tested against Citect versions 5, 6, and 7 ...
## # $Id: citect_scada_odbcrb ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/projects/Framework/ ## # # # msfcli exploit/windows/misc/citect_scada_o ...
## # $Id: citect_scada_odbcrb 11039 2010-11-14 19:03:24Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' cla ...