SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-0774

Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via…

MEDIUM 6.9EPSS 0.47%

Does this matter?

Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.

Description

Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.

CVSS 2.0
6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS
0.47% probability · 39th percentile
CISA KEV
Not listed
Weakness
CWE-121, CWE-119
Affected
schneider-electric/ofs test client tlxcdlfofs33 · schneider-electric/ofs test client tlxcdltofs33 · schneider-electric/ofs test client tlxcdluofs33 · schneider-electric/ofs test client tlxcdstofs33 · schneider-electric/ofs test client tlxcdsuofs33 · schneider-electric/opc factory server
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.