Vulnerability record · CVE-2008-4322 · published 29 September 2008
CVE-2008-4322: RealWin Server stack buffer overflow via FC_INFOTAG/SET_CONTROL packet
RRealflex Technologies Ltd · Realwin Server
RealFlex RealWin Server 2.0, as distributed by DATAC, contains a stack-based buffer overflow (CWE-119) reachable through a crafted FC_INFOTAG/SET_CONTROL packet. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the server. The record does not list affected version ranges beyond RealWin Server 2.0.
Description
Stack-based buffer overflow in RealFlex Technologies Ltd. RealWin Server 2.0, as distributed by DATAC, allows remote attackers to execute arbitrary code via a crafted FC_INFOTAG/SET_CONTROL packet.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10.0 with network reachability, no authentication and full code execution impact, combined with public exploit references and a very high EPSS score.
What it is
RealFlex RealWin Server 2.0, as distributed by DATAC, contains a stack-based buffer overflow (CWE-119) reachable through a crafted FC_INFOTAG/SET_CONTROL packet. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the server. The record does not list affected version ranges beyond RealWin Server 2.0.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the RealWin Server process, which per the CVSS vector implies full loss of confidentiality, integrity and availability. This is a network-facing industrial control server, so compromise can affect connected control operations.
Attack surface
Reached over the network (AV:N) with no authentication (Au:N) and no user interaction, by sending a malformed FC_INFOTAG/SET_CONTROL packet to the server. The record does not specify the exact port or protocol details.
Exploitation
Public exploit references exist (SecurityFocus BID 31418 and the reversemode.com advisory are tagged Exploit), and EPSS is 0.6507 (99.2nd percentile), indicating high near-term exploitation likelihood. The CVE is not listed in CISA KEV and no ransomware use is documented.
What to do
- Apply the vendor fix or upgrade from RealWin Server 2.0 to a supported, patched release; consult the Secunia/DATAC advisory for the corrected build.
- If no patch is available, isolate RealWin Server hosts behind a firewall and restrict the service port to trusted engineering workstations only.
- Disable or block the FC_INFOTAG/SET_CONTROL interface from untrusted networks where it is not required.
- Segment the control network so a compromised RealWin Server cannot reach other ICS assets, and monitor for unexpected outbound traffic from the host.
- Treat the host as untrusted if exploitation is suspected and rebuild it from a known-good image.
Detection
- Monitor network traffic for malformed or oversized FC_INFOTAG/SET_CONTROL packets to the RealWin Server port.
- Alert on RealWin Server process crashes or restarts, which can indicate a failed overflow attempt.
- Watch for unexpected child processes, shell execution or outbound connections originating from the RealWin Server host.
- Use IDS/IPS signatures for CVE-2008-4322 where available and review logs for repeated connection attempts from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-4322 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-4322), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.