CVE-2008-4322
RealWin Server 2.0 - Remote Code Execution via Crafted FC_INFOTAG/SET_CONTROL Packet
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-4322.
PoCs published by Metasploit, MC, including Metasploit module exploits/windows/scada/realwin.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in DATAC RealWin SCADA Server via a crafted FC_INFOTAG/SET_CONTROL packet, allowing arbitrary code execution. It targets version 2.0 (Build 6.0.10.37) and uses a universal return address for reliability.
Description
Stack-based buffer overflow in RealFlex Technologies Ltd. RealWin Server 2.0, as distributed by DATAC, allows remote attackers to execute arbitrary code via a crafted FC_INFOTAG/SET_CONTROL packet.
Exploits (2)
This Metasploit module exploits a stack buffer overflow in DATAC RealWin SCADA Server via a crafted FC_INFOTAG/SET_CONTROL packet, allowing arbitrary code execution. It targets version 2.0 (Build 6.0.10.37) and uses a universal return address for reliability.
This Metasploit module exploits a stack buffer overflow in DATAC RealWin SCADA Server via a crafted FC_INFOTAG/SET_CONTROL packet, allowing arbitrary code execution. It targets a specific return address and includes a payload with NOP sleds and bad character avoidance.