Unrated severityNVD Advisory· Published Jun 16, 2008· Updated Apr 23, 2026
CVE-2008-2639
CVE-2008-2639
Description
Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to execute arbitrary code via a long string in the second application packet in a TCP session on port 20222.
Affected products
3- cpe:2.3:a:citect:citectfacilities:7:*:*:*:*:*:*:*
cpe:2.3:a:citect:citectscada:6:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:citect:citectscada:6:*:*:*:*:*:*:*
- cpe:2.3:a:citect:citectscada:7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- secunia.com/advisories/30638nvdVendor Advisory
- www.kb.cert.org/vuls/id/476345nvdUS Government Resource
- isc.sans.org/diary.htmlnvd
- securityreason.com/securityalert/3944nvd
- securitytracker.com/idnvd
- www.coresecurity.comnvd
- www.kb.cert.org/vuls/id/CTAR-7ENQNHnvd
- www.securityfocus.com/archive/1/493272/100/0/threadednvd
- www.securityfocus.com/bid/29634nvd
- www.vupen.com/english/advisories/2008/1834/referencesnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/42992nvd
- www.exploit-db.com/exploits/6387nvd
News mentions
0No linked articles in our index yet.