DATAC RealWin SCADA Server Remote Stack Buffer Overflow Vulnerability
BID:31418
Info
DATAC RealWin SCADA Server Remote Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 31418 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4322 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | Ruben Santamarta |
| Vulnerable: |
DATAC Control International RealWin SCADA Server 2.0 |
| Not Vulnerable: | |
Discussion
DATAC RealWin SCADA Server Remote Stack Buffer Overflow Vulnerability
DATAC RealWin SCADA server is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. This may facilitate the complete compromise of affected computers. Failed exploit attempts may result in a denial-of-service condition.
RealWin SCADA server 2.0 is affected; other versions may also be vulnerable.
DATAC RealWin SCADA server is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. This may facilitate the complete compromise of affected computers. Failed exploit attempts may result in a denial-of-service condition.
RealWin SCADA server 2.0 is affected; other versions may also be vulnerable.
Exploit / POC
DATAC RealWin SCADA Server Remote Stack Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
DATAC RealWin SCADA Server Remote Stack Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
DATAC RealWin SCADA Server Remote Stack Buffer Overflow Vulnerability
References:
References:
- RealWin Homepage (DATAC )
- DATAC RealWin 2.0 SCADA Software - Remote PreaAuth Exploit (Reversemode
) - Vulnerability Note VU#976484 DATAC RealWin buffer overflow (US-CERT)