|
|
|
Vulnerability Note VU#476345Citect CitectSCADA buffer overflowOverviewCitect CitectSCADA contains a remotely accessible buffer overflow vulnerability which may allow a remote attacker to execute arbitrary code.I. DescriptionCitect CitectSCADA is software used for monitoring and control in Supervisory Control And Data Acquisition (SCADA) systems. A buffer overflow vulnerability exists in a CitectSCADA process that listens on the network (20222/tcp) for service requests from clients. An attacker could exploit this vulnerability by sending specially crafted packets to a vulnerable CitectSCADA system.Note that this vulnerability affects versions of Citect CitectSCADA and CitectFacilities. Supported Citect customers should contact Citect to receive a patch. For more information on contacting Citect visit http://www.citect.com/index.php?option=com_content&task=view&id=26&Itemid=29.
References
Thanks to Ivan Arce at Core Securities for information that was used in this report. This document was written by Chris Taschner.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||