« Volver al listado

CVE-2008-2474

Estado: ModificadaAlta (10)—

Desbordamiento de búfer en x87 anteriores a v3.5.5 en ABB Process Comunicatión Unit 400 (PCU400) v4.4 hasta v4.6, permite a atacantes remotos ejecutar código arbitrario a través de un paquete manipulado utilizando los protocolos de comunicación (1)IEC60870-5-101 o (2) IEC60870-5-104 para el interfaz web del X87.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-2474",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-09-29T17:17:29.050",
  "references": [
    {
      "url": "http://secunia.com/advisories/32047",
      "source": "cret@cert.org"
    },
    {
      "url": "http://securityreason.com/securityalert/4320",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/343971",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/CTAR-7JTNRX",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/496739/100/0/threaded",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/31391",
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/32047",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/4320",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/343971",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/CTAR-7JTNRX",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/496739/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/31391",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attackers to execute arbitrary code via a crafted packet using the (1) IEC60870-5-101 or (2) IEC60870-5-104 communication protocol to the X87 web interface."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer en x87 anteriores a v3.5.5 en ABB Process Comunicatión Unit 400 (PCU400) v4.4 hasta v4.6, permite a atacantes remotos ejecutar código arbitrario a través de un paquete manipulado utilizando los protocolos de comunicación (1)IEC60870-5-101 o (2) IEC60870-5-104 para el interfaz web del X87."
    }
  ],
  "lastModified": "2026-06-16T22:53:50.220",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:abb:pcu400:4.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "053989DE-274C-4000-83E2-3B6BB13C72A3"
            },
            {
              "criteria": "cpe:2.3:h:abb:pcu400:4.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F189832-AAE9-467D-ACC0-F1DD81C1DA5E"
            },
            {
              "criteria": "cpe:2.3:h:abb:pcu400:4.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50B1D03E-E73B-4759-A841-CEBE6CA7F4F8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org",
  "evaluatorSolution": "This issue is corrected in version 3.5.5 of the x87 executable. To obtain a patch or upgrade software please contact your vendor. The x87 executable is considered obsolete in newer versions of the PCU 400 and should be replaced\r\nby the newer x88 or x89 executable where applicable.\r\n\r\nLink to contact information: http://www.abb.com/industries/db0003db004333/c12573e7003305cbc1257074003d0702.aspx?productLanguage=us&country=US&tabKey=Contacts"
}