CVE-2008-2474
Status: ModifiedHigh (10)—
Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attackers to execute arbitrary code via a crafted packet using the (1) IEC60870-5-101 or (2) IEC60870-5-104 communication protocol to the X87 web interface.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Base score: 10
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 7.88%
- Percentile among all scored CVEs: 95
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-119
References
- http://secunia.com/advisories/32047
- http://securityreason.com/securityalert/4320
- http://www.kb.cert.org/vuls/id/343971
- http://www.kb.cert.org/vuls/id/CTAR-7JTNRX
- http://www.securityfocus.com/archive/1/496739/100/0/threaded
- http://www.securityfocus.com/bid/31391
- http://secunia.com/advisories/32047
- http://securityreason.com/securityalert/4320
- http://www.kb.cert.org/vuls/id/343971
- http://www.kb.cert.org/vuls/id/CTAR-7JTNRX
- http://www.securityfocus.com/archive/1/496739/100/0/threaded
- http://www.securityfocus.com/bid/31391
Raw JSON (NVD)
Show
{
"id": "CVE-2008-2474",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-09-29T17:17:29.050",
"references": [
{
"url": "http://secunia.com/advisories/32047",
"source": "cret@cert.org"
},
{
"url": "http://securityreason.com/securityalert/4320",
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/343971",
"tags": [
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/CTAR-7JTNRX",
"source": "cret@cert.org"
},
{
"url": "http://www.securityfocus.com/archive/1/496739/100/0/threaded",
"source": "cret@cert.org"
},
{
"url": "http://www.securityfocus.com/bid/31391",
"source": "cret@cert.org"
},
{
"url": "http://secunia.com/advisories/32047",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/4320",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/343971",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/CTAR-7JTNRX",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/496739/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/31391",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attackers to execute arbitrary code via a crafted packet using the (1) IEC60870-5-101 or (2) IEC60870-5-104 communication protocol to the X87 web interface."
},
{
"lang": "es",
"value": "Desbordamiento de búfer en x87 anteriores a v3.5.5 en ABB Process Comunicatión Unit 400 (PCU400) v4.4 hasta v4.6, permite a atacantes remotos ejecutar código arbitrario a través de un paquete manipulado utilizando los protocolos de comunicación (1)IEC60870-5-101 o (2) IEC60870-5-104 para el interfaz web del X87."
}
],
"lastModified": "2026-06-16T22:53:50.220",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:abb:pcu400:4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "053989DE-274C-4000-83E2-3B6BB13C72A3"
},
{
"criteria": "cpe:2.3:h:abb:pcu400:4.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F189832-AAE9-467D-ACC0-F1DD81C1DA5E"
},
{
"criteria": "cpe:2.3:h:abb:pcu400:4.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50B1D03E-E73B-4759-A841-CEBE6CA7F4F8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org",
"evaluatorSolution": "This issue is corrected in version 3.5.5 of the x87 executable. To obtain a patch or upgrade software please contact your vendor. The x87 executable is considered obsolete in newer versions of the PCU 400 and should be replaced\r\nby the newer x88 or x89 executable where applicable.\r\n\r\nLink to contact information: http://www.abb.com/industries/db0003db004333/c12573e7003305cbc1257074003d0702.aspx?productLanguage=us&country=US&tabKey=Contacts"
}