CVE-2008-2639: Buffer Overflow
Published Jun 16, 2008
·Updated
Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to execute arbitrary code via a long string in the second application packet in a TCP session on port 20222.
Affected Software
3 affected components
Citect CitectFacilities=7
Citect CitectSCADA=6
Citect CitectSCADA=7
Event History
Jun 16, 2008
CVE Published
via MITRE·06:26 PM
Data Sourced
via MITRE·06:26 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2639?
CVE-2008-2639 has a critical severity rating due to the potential for remote code execution.
2
How do I fix CVE-2008-2639?
To fix CVE-2008-2639, apply the latest patches or updates provided by Citect for the affected versions.
3
What products are affected by CVE-2008-2639?
CVE-2008-2639 affects CitectSCADA versions 6 and 7 as well as CitectFacilities version 7.
4
Can CVE-2008-2639 be exploited remotely?
Yes, CVE-2008-2639 can be exploited remotely through a long string in a TCP session on port 20222.
5
What type of vulnerability is CVE-2008-2639?
CVE-2008-2639 is a stack-based buffer overflow vulnerability.