CVE-2014-0774
Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via…
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-121, CWE-119
- Affected
- schneider-electric/ofs test client tlxcdlfofs33 · schneider-electric/ofs test client tlxcdltofs33 · schneider-electric/ofs test client tlxcdluofs33 · schneider-electric/ofs test client tlxcdstofs33 · schneider-electric/ofs test client tlxcdsuofs33 · schneider-electric/opc factory server
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/65871
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-031-01
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-058-02
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-031-01Vendor Advisory
- http://ics-cert.us-cert.gov/advisories/ICSA-14-058-02Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/65871
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.