| PROBLEM: | Citect CitectSCADA contains a remotely accessible buffer overflow vulnerability which may allow a remote attacker to execute arbitrary code. |
| PLATFORM: | Citect CitectSCADA CitectFacilities |
| DAMAGE: | Execute arbitrary code or DoS. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. A remote, unauthenticated attacker may be able to execute arbitrary code or cause a denial of service. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
6.4 5.3 (AV:N/AC:L/Au:N/C:P/I:P/A:N/E:F/RL:OF/RC:C) |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-320.shtml |
| ORIGINAL BULLETIN: | http://www.kb.cert.org/vuls/id/476345 |
| CVE: | CVE-2008-2639 |
[***** Start US-CERT Vulnerability Note VU#476345 *****]
Note that this vulnerability affects versions of Citect CitectSCADA and CitectFacilities.
Supported Citect customers should contact Citect to receive a patch. For more information on contacting Citect visit http://www.citect.com/index.php?option=com_content&task=view&id=26&Itemid=29.
Restrict access
Restricting access to a vulnerable system by using host or network based firewalls may prevent a remote attacker from exploiting this vulnerability. For more information refer to Citect security article Securing Your SCADA Network.
| Vendor | Status | Date Updated |
|---|---|---|
| Citect | Vulnerable | 11-Jun-2008 |
http://www.citect.com/index.php?option=com_content&task=view&id=186&Itemid=322
http://www.citect.com/index.php?option=com_content&task=view&id=26&Itemid=29
http://www.citect.com/documents/news_and_media/pr-citect-address-security.pdf
http://www.coresecurity.com/index.php5?module=ContentMod&action=item&id=2186
http://secunia.com/advisories/30638/
http://www.securityfocus.com/bid/29634/discuss
Thanks to Ivan Arce at Core Securities for information that was used in this report.
This document was written by Chris Taschner.
| Date Public | 07/11/2008 |
| Date First Published | 06/11/2008 12:55:41 PM |
| Date Last Updated | 06/17/2008 |
| CERT Advisory | |
| CVE Name | CVE-2008-2639 |
| US-CERT Technical Alerts | |
| Metric | 3.57 |
| Document Revision | 14 |
[***** End US-CERT Vulnerability Note VU#476345 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org