CVE-2013-0657
published 2013-01-21CVE-2013-0657: Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by…
PriorityP271critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
21.26%
97.3th percentile
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-12397 data that does not comply with a protocol.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | interactive_graphical_scada_system | <= 10.0 | — |
| schneider-electric | interactive_graphical_scada_system | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert tcp any any -> $HOME_NET 12397 (msg:"ET SCADA SEIG SYSTEM 9 - Remote Code Execution"; flow:established,to_server; content:"|14 60 00 00 66 66 07 00 10 00 00 00 19 00 00 00 00 00 04 00 00 00 60 00|"; depth:24; content:!"|0d|"; distance:0; content:!"|0a|"; distance:0; content:!"|ff|"; content:!"|00|"; distance:0; reference:url,exploit-db.com/exploits/45218/; reference:cve,2013-0657; classtype:attempted-user; sid:2026003; rev:1;)
bytes
|14 60 00 00 66 66 07 00 10 00 00 00 19 00 00 00 00 00 04 00 00 00 60 00|
- →Monitor for TCP connections to port 12397 carrying out-of-protocol data; the Snort/ET rule triggers on a 24-byte magic header |14 60 00 00 66 66 07 00 10 00 00 00 19 00 00 00 00 00 04 00 00 00 60 00| at depth 24 with absence of bytes 0x0D, 0x0A, 0xFF, and 0x00.
- →The exploit uses a two-stage attack: Write packets (opcode 0x0D) to TCP/12401 drop a payload EXE, then an EXE packet (opcode 0x0A) to TCP/12397 triggers dc.exe to execute it via CreateProcessA. Alert on sequential connections to both ports from the same source. ↗
- →Dropped payload EXE lands in C:\Documents and Settings\All Users\Application Data\7T\ — monitor this directory for unexpected executable creation. ↗
- →The exploit bypasses SafeSEH via exprsrv.dll (a library compiled without SafeSEH). Presence of a return address pointing into exprsrv.dll during a crash/exception in dc.exe is a strong indicator of exploitation. ↗
- →IGSS communicates over both TCP/12397 and TCP/12399 by default; firewall rules should restrict these ports to known ICS device IPs only. ↗
- ·The ROP gadget address (0x0F9C520B in exprsrv.dll) is version-specific to IGSS v9 on Windows 7 x86; it will differ across OS versions and IGSS patch levels. ↗
- ·The Metasploit module notes that service packs do not influence exploitability, but targets are limited to Windows XP, Windows 7, and Windows Server 2003/R2. ↗
- ·The shellcode uses EXITFUNC=thread; without this, the application enters a resource-exhausting loop. Detection of missing EXITFUNC may indicate a DoS-only payload variant. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric IGSS Buffer Overflow
cisa_ics·2013-05-06
Schneider Electric IGSS Buffer Overflow
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric IGSS Buffer Overflow
Last RevisedMay 06, 2013
Alert CodeICSA-13-018-01
## Overview
Independent researcher Aaron Portnoy of Exodus Intelligence has identified a buffer overflow vulnerability in Schneider Electric’s Interactive Graphical SCADA System (IGSS) application. Schneider Electric has produced a patch that fully resolves this vulnerability. Aaron Portnoy has validated this patch. This vulnerability could be exploited remotely.
## Affected Products
The Schneider Electric products affected:
- IGSS application, all versions.
## Impact
An exploit of thi
GHSA
GHSA-qw55-52cc-p8hc: Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrar
ghsa_unreviewed·2022-05-14
CVE-2013-0657 [HIGH] CWE-119 GHSA-qw55-52cc-p8hc: Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrar
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-12397 data that does not comply with a protocol.
Suricata
ET SCADA SEIG SYSTEM 9 - Remote Code Execution
suricata·2018-08-21
CVE-2013-0657 ET SCADA SEIG SYSTEM 9 - Remote Code Execution
ET SCADA SEIG SYSTEM 9 - Remote Code Execution
Rule: alert tcp any any -> $HOME_NET 12397 (msg:"ET SCADA SEIG SYSTEM 9 - Remote Code Execution"; flow:established,to_server; content:"|14 60 00 00 66 66 07 00 10 00 00 00 19 00 00 00 00 00 04 00 00 00 60 00|"; depth:24; content:!"|0d|"; distance:0; content:!"|0a|"; distance:0; content:!"|ff|"; content:!"|00|"; distance:0; reference:url,exploit-db.com/exploits/45218/; reference:cve,2013-0657; classtype:attempted-user; sid:2026003; rev:1; metadata:created_at 2018_08_21, cve CVE_2013_0657, confidence High, signature_severity Major, updated_at 2019_07_26, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Exploit-DB
SEIG SCADA System 9 - Remote Code Execution
exploitdb·2018-08-19·CVSS 10.0
CVE-2013-0657 [CRITICAL] SEIG SCADA System 9 - Remote Code Execution
SEIG SCADA System 9 - Remote Code Execution
---
# Title: SEIG SCADA SYSTEM 9 - Remote Code Execution
# Author: Alejandro Parodi
# Date: 2018-08-17
# Vendor Homepage: https://www.schneider-electric.com
# Software Link: https://www.schneider-electric.ie/en/download/document/V9_Full_installation_package_register_and_receive_file/
# Version: v9
# Tested on: Windows7 x86
# CVE: CVE-2013-0657
# References:
# https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0657
import socket
import struct
ip = "192.168.0.23"
port = 12397
con = (ip, port)
# DoS Payload found in the research (CRUNCHBASE UNEXPECTED PARAMETER)
# length = "\x00\x70\x00\x00\x00\x00\x00\x00"
# message = "\x00\x70AA\x65\x00\x00\x00AAAAAAAAAAAAAAAA\x00\x00\x00\x00"+"B"*28644
# payload = length+message
# Exploit Magic
message
Exploit-DB
7-Technologies IGSS 9 - Data Server/Collector Packet Handling (Metasploit)
exploitdb·2011-05-30
CVE-2013-0657 7-Technologies IGSS 9 - Data Server/Collector Packet Handling (Metasploit)
7-Technologies IGSS 9 - Data Server/Collector Packet Handling (Metasploit)
---
##
# $Id: igss9_misc.rb 12779 2011-05-31 14:33:19Z swtornio $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 "7-Technologies IGSS 9 Data Server/Collector Packet Handling Vulnerabilities",
'Description' => %q{
This module exploits multiple vulnerabilities found on IGSS 9's Data Server and
Data Collector services. The initial approach is first by transferring our binary
with Write packets (opcode 0x0D) via port 12401 (igssdataserver.exe), and then send
an EXE packe
http://igss.schneider-electric.com/igss/igssupdates/v100/progupdatesv100.ziphttp://igss.schneider-electric.com/igss/igssupdates/v90/progupdatesv90.ziphttp://www.us-cert.gov/control_systems/pdf/ICSA-13-018-01.pdfhttps://www.exploit-db.com/exploits/45218/http://igss.schneider-electric.com/igss/igssupdates/v100/progupdatesv100.ziphttp://igss.schneider-electric.com/igss/igssupdates/v90/progupdatesv90.ziphttp://www.us-cert.gov/control_systems/pdf/ICSA-13-018-01.pdfhttps://www.exploit-db.com/exploits/45218/
2013-01-21
Published