RULE(RULE ID:711186)

Rule General Information
Release Date: 2017-06-16
Rule Name: Citectscada ODBC Server Remote Stack Based Buffer Overflow Vulnerability -5 (CVE-2008-2639)
Severity:
CVE ID:
Rule Protection Details
Description: Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to execute arbitrary code via a long string in the second application packet in a TCP session on port 20222.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Others
Reference: SecurityFocusBID:29634
ExploitDB:6387
http://isc.sans.org/diary.html?storyid=4556
http://securityreason.com/securityalert/3944
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://www.citect.com/index.php?option=com_content&task=view&id=1374&Itemid=223