CVE-2009-4462
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
30/12/2009
Last modified:
09/04/2025
Description
Stack-based buffer overflow in the NetBiterConfig utility (NetBiterConfig.exe) 1.3.0 for Intellicom NetBiter WebSCADA allows remote attackers to execute arbitrary code via a long hn (hostname) parameter in a crafted HICP-protocol UDP packet.
Impact
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:intellicom:netbiterconfig:1.3.0:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intellicom:netbiter_webscada_ws100:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:intellicom:netbiter_webscada_ws200:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://blog.48bits.com/2009/12/12/exposing-hms-hicp-protocol-0day-light/
- http://reversemode.com/index.php?option=com_content&task=view&id=65&Itemid=1
- http://support.intellicom.se/getfile.cfm?FID=150&FPID=85
- http://www.kb.cert.org/vuls/id/181737
- http://www.securityfocus.com/archive/1/508449/100/0/threaded
- http://www.securityfocus.com/bid/37325
- http://www.vupen.com/english/advisories/2009/3542
- http://blog.48bits.com/2009/12/12/exposing-hms-hicp-protocol-0day-light/
- http://reversemode.com/index.php?option=com_content&task=view&id=65&Itemid=1
- http://support.intellicom.se/getfile.cfm?FID=150&FPID=85
- http://www.kb.cert.org/vuls/id/181737
- http://www.securityfocus.com/archive/1/508449/100/0/threaded
- http://www.securityfocus.com/bid/37325
- http://www.vupen.com/english/advisories/2009/3542



