CVE-2010-4740

SCADA Engine BACnet OPC Client <1.0.25 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2010-4740. PoCs published by Jeremy Brown, Jeremy Brown, MC, including Metasploit module exploits/windows/fileformat/bacnet_csv.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in BACnet OPC Client 1.0.24 by crafting a malicious CSV file that triggers a stack-based overflow, leading to arbitrary code execution via a JMP ESP technique.

Description

Stack-based buffer overflow in WTclient.dll in SCADA Engine BACnet OPC Client before 1.0.25 allows user-assisted remote attackers to execute arbitrary code via a crafted .csv file, related to a status log message.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Jeremy Brown · pythonlocalwindows
https://www.exploit-db.com/exploits/15026

This exploit targets a buffer overflow vulnerability in BACnet OPC Client 1.0.24 by crafting a malicious CSV file that triggers a stack-based overflow, leading to arbitrary code execution via a JMP ESP technique.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: BACnet OPC Client 1.0.24
No auth needed
Prerequisites: Victim must open the malicious CSV file in the vulnerable BACnet OPC Client
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GOOD
by Jeremy Brown, MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/bacnet_csv.rb

This Metasploit module exploits a stack buffer overflow in SCADA Engine BACnet OPC Client v1.0.24 by crafting a malicious CSV file that triggers arbitrary code execution when parsed.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SCADA Engine BACnet OPC Client v1.0.24
No auth needed
Prerequisites: Victim must open the malicious CSV file in the vulnerable BACnet OPC Client
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
US Government Resource x_refsource_misc
http://www.us-cert.gov/control_systems/pdf/ICSA-10-264-01.pdf
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8083
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/41466
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/43289
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/660688

Scores

EPSS 0.4162
EPSS Percentile 98.5%

Details

CWE
CWE-119
Status published
Products (1)
scadaengine/bacnet_opc_client < 1.0.24
Published Feb 16, 2011
Tracked Since Feb 18, 2026