CVE-2013-0657

Schneider Electric IGSS <10 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2013-0657. PoCs published by Metasploit, Alejandro Parodi.

AI-analyzed exploit summary This Metasploit module exploits CVE-2013-0657 by leveraging two vulnerabilities in 7-Technologies IGSS 9: a Write File packet flaw (opcode 0x0D) to upload a payload to the Data Server (port 12401) and an EXE packet flaw (opcode 0x0A) to execute the payload via the Data Collector (port 12397).

Description

Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-12397 data that does not comply with a protocol.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/17352

This Metasploit module exploits CVE-2013-0657 by leveraging two vulnerabilities in 7-Technologies IGSS 9: a Write File packet flaw (opcode 0x0D) to upload a payload to the Data Server (port 12401) and an EXE packet flaw (opcode 0x0A) to execute the payload via the Data Collector (port 12397).

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: 7-Technologies IGSS 9 Data Server/Collector
No auth needed
Prerequisites: Network access to ports 12401 and 12397 on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Alejandro Parodi · pythonremotewindows_x86
https://www.exploit-db.com/exploits/45218

This exploit targets a buffer overflow vulnerability in SEIG SCADA SYSTEM 9, allowing remote code execution via a crafted payload sent to port 12397. The payload includes a SafeSEH bypass and a shellcode to execute 'calc.exe' as a proof of concept.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Schneider Electric SEIG SCADA SYSTEM v9
No auth needed
Prerequisites: Network access to the target system · Target system running SEIG SCADA SYSTEM v9
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Patch, US Government Resource x_refsource_misc
http://www.us-cert.gov/control_systems/pdf/ICSA-13-018-01.pdf
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45218/

Scores

EPSS 0.2126
EPSS Percentile 97.3%

Details

CWE
CWE-119
Status published
Products (2)
schneider-electric/interactive_graphical_scada_system 9.0
schneider-electric/interactive_graphical_scada_system < 10.0
Published Jan 21, 2013
Tracked Since Feb 18, 2026