CVE-2008-2639 describes a stack-based buffer overflow in the ODBC server service of Citect CitectSCADA 6 and 7, and CitectFacilities 7. This critical vulnerability allows remote attackers to execute arbitrary code by sending a specially crafted, long string in the second application packet during a TCP session on port 20222. With a CVSS score of 7.6 and an EPSS score of 0.85791, this vulnerability is considered highly severe, requiring no authentication and offering complete compromise of confidentiality, integrity, and availability. While not currently on the KEV catalog or Hot List, public exploit modules exist in Metasploit and ExploitDB, indicating readily available exploit code, though there is no significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7CPE matchmatch criteria | cpe:2.3:a:citect:citectfacilities:7:*:*:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:a:citect:citectscada:6:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:a:citect:citectscada:7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.