Exploitation Summary
EIP tracks 2 public exploits for CVE-2009-4462. PoCs published by Ruben Santamarta.
AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in Intellicom NetBiterConfig.exe 1.3.0 by sending a maliciously crafted UDP packet with an oversized 'hn' (hostname) field. The overflow can lead to arbitrary code execution or denial-of-service.
Description
Stack-based buffer overflow in the NetBiterConfig utility (NetBiterConfig.exe) 1.3.0 for Intellicom NetBiter WebSCADA allows remote attackers to execute arbitrary code via a long hn (hostname) parameter in a crafted HICP-protocol UDP packet.
Exploits (2)
This exploit targets a stack-based buffer overflow in Intellicom NetBiterConfig.exe 1.3.0 by sending a maliciously crafted UDP packet with an oversized 'hn' (hostname) field. The overflow can lead to arbitrary code execution or denial-of-service.
This exploit targets a stack-based buffer overflow in Intellicom NetBiterConfig.exe 1.3.0 via a maliciously crafted UDP packet sent to port 3250. The overflow occurs due to an unsafe strcpy operation when processing the 'hn' (hostname) parameter, allowing remote code execution when the admin interacts with the list box item.