MEDIUM · 6.8

CVE-2014-0774

Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33...

Vulnerability Description

Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.

CVSS Score

6.8

MEDIUM

AV:L/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Schneider-ElectricOfs Test Client Tlxcdlfofs333.35
Schneider-ElectricOfs Test Client Tlxcdltofs333.35
Schneider-ElectricOfs Test Client Tlxcdluofs333.35
Schneider-ElectricOfs Test Client Tlxcdstofs333.35
Schneider-ElectricOfs Test Client Tlxcdsuofs333.35
Schneider-ElectricOpc Factory Server3.35

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-0774?

CVE-2014-0774 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33...

How severe is CVE-2014-0774?

CVE-2014-0774 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-0774?

Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Ofs Test Client Tlxcdlfofs33, Schneider-Electric Ofs Test Client Tlxcdltofs33, Schneider-Electric Ofs Test Client Tlxcdluofs33, Schneider-Electric Ofs Test Client Tlxcdstofs33, Schneider-Electric Ofs Test Client Tlxcdsuofs33.