Vulnerability record · CVE-2008-2639 · published 16 June 2008
CVE-2008-2639: CitectSCADA ODBC server stack buffer overflow allows remote code execution
Citect · Citectfacilities
The ODBC server service in Citect CitectSCADA 6 and 7 and CitectFacilities 7 contains a stack-based buffer overflow (CWE-119) triggered by a long string in the second application packet of a TCP session on port 20222. A remote, unauthenticated attacker can corrupt the stack and execute arbitrary code, which matters because SCADA/HMI systems are high-value industrial control targets.
Description
Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to execute arbitrary code via a long string in the second application packet in a TCP session on port 20222.
AV:N/AC:H/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote unauthenticated code execution in an industrial control product with public exploit code and very high EPSS, though the attack complexity is rated high and no KEV listing exists.
What it is
The ODBC server service in Citect CitectSCADA 6 and 7 and CitectFacilities 7 contains a stack-based buffer overflow (CWE-119) triggered by a long string in the second application packet of a TCP session on port 20222. A remote, unauthenticated attacker can corrupt the stack and execute arbitrary code, which matters because SCADA/HMI systems are high-value industrial control targets.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the ODBC server service, potentially allowing full compromise of the SCADA host and onward access to the control network.
Attack surface
Reachable over the network via TCP port 20222; the CVSS vector (AV:N/Au:N) indicates no authentication is required, and the description implies no user interaction beyond sending crafted packets to the service.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.777, 99.5th percentile) and a public Exploit-DB entry (6387) exists, indicating exploit code is available.
What to do
- Apply the vendor patch or upgrade to a fixed CitectSCADA/CitectFacilities release as the first action.
- Block or restrict TCP port 20222 to only trusted engineering and control hosts using host or network firewalls.
- Segment SCADA networks from IT and internet-facing networks so the ODBC service is not reachable from untrusted sources.
- If the ODBC server service is not required, disable it to remove the attack surface.
- Monitor vendor and CERT/CC advisories for updated guidance on affected versions.
Detection
- Alert on network connections to TCP port 20222 from unexpected or external hosts.
- Inspect packet captures for oversized or malformed second application packets in ODBC server sessions.
- Monitor the SCADA host for service crashes or unexpected process restarts of the ODBC server.
- Watch for anomalous child processes or command execution spawned by the ODBC server service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-2639 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-2639), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.