CVE-2009-4462
high · 10Stack-based buffer overflow in the NetBiterConfig utility (NetBiterConfig.exe) 1.3.0 for Intellicom NetBiter WebSCADA allows remote attackers to execute arbitrary code via a long hn (hostname) parameter in a crafted HICP-protocol UDP packet.
10
CVSS
20.0%
EPSS (exploit prob.)
97th
EPSS percentile
2009-12-30
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| intellicom | netbiterconfig | 1.3.0 |
| intellicom | netbiter_webscada_ws100 | all versions |
| intellicom | netbiter_webscada_ws200 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://blog.48bits.com/2009/12/12/exposing-hms-hicp-protocol-0day-light/
- http://reversemode.com/index.php?option=com_content&task=view&id=65&Itemid=1
- http://support.intellicom.se/getfile.cfm?FID=150&FPID=85
- http://www.kb.cert.org/vuls/id/181737
- http://www.securityfocus.com/archive/1/508449/100/0/threaded
- http://www.securityfocus.com/bid/37325
- http://www.vupen.com/english/advisories/2009/3542
- http://blog.48bits.com/2009/12/12/exposing-hms-hicp-protocol-0day-light/
- http://reversemode.com/index.php?option=com_content&task=view&id=65&Itemid=1
- http://support.intellicom.se/getfile.cfm?FID=150&FPID=85
- http://www.kb.cert.org/vuls/id/181737
- http://www.securityfocus.com/archive/1/508449/100/0/threaded
- http://www.securityfocus.com/bid/37325
- http://www.vupen.com/english/advisories/2009/3542
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-4462