CVE-2014-0774
Published Feb 28, 2014
Last updated 9 years ago
Overview
- Description
- Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.9
- Impact score
- 10
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-119
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:schneider-electric:ofs_test_client_tlxcdlfofs33:3.35:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36AB0685-A0FE-4465-8C9E-7C633AAE0584" }, { "criteria": "cpe:2.3:a:schneider-electric:ofs_test_client_tlxcdltofs33:3.35:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "16B1D3C2-7A1B-403F-A2BE-01BAC2C01E74" }, { "criteria": "cpe:2.3:a:schneider-electric:ofs_test_client_tlxcdluofs33:3.35:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B58EF88-D1BC-4858-A3DA-505D72EE46E3" }, { "criteria": "cpe:2.3:a:schneider-electric:ofs_test_client_tlxcdstofs33:3.35:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06B8043C-3542-4B8F-82BE-E1E8A8E067F3" }, { "criteria": "cpe:2.3:a:schneider-electric:ofs_test_client_tlxcdsuofs33:3.35:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1EF80DC0-7948-4E95-B090-14CC482B9DE5" }, { "criteria": "cpe:2.3:a:schneider-electric:opc_factory_server:3.35:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F8874360-6B9A-40C3-A95F-8FD18F73244D" } ], "operator": "OR" } ] } ]