Vulnerability Description
Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Ofs Test Client Tlxcdlfofs33 | 3.35 |
| Schneider-Electric | Ofs Test Client Tlxcdltofs33 | 3.35 |
| Schneider-Electric | Ofs Test Client Tlxcdluofs33 | 3.35 |
| Schneider-Electric | Ofs Test Client Tlxcdstofs33 | 3.35 |
| Schneider-Electric | Ofs Test Client Tlxcdsuofs33 | 3.35 |
| Schneider-Electric | Opc Factory Server | 3.35 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/65871
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-031-01
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-058-02
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-031-01Vendor Advisory
- http://ics-cert.us-cert.gov/advisories/ICSA-14-058-02Third Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/65871
FAQ
What is CVE-2014-0774?
CVE-2014-0774 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33...
How severe is CVE-2014-0774?
CVE-2014-0774 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0774?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Ofs Test Client Tlxcdlfofs33, Schneider-Electric Ofs Test Client Tlxcdltofs33, Schneider-Electric Ofs Test Client Tlxcdluofs33, Schneider-Electric Ofs Test Client Tlxcdstofs33, Schneider-Electric Ofs Test Client Tlxcdsuofs33.