cbcvebase.
CVE-2014-0774
published 2014-02-28

CVE-2014-0774: Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 -…

PriorityP425medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.47%
37.3th percentile
Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.

Affected

11 ranges
VendorProductVersion rangeFixed in
schneider-electricofs_test_client_tlxcdlfofs33
schneider-electricofs_test_client_tlxcdltofs33
schneider-electricofs_test_client_tlxcdluofs33
schneider-electricofs_test_client_tlxcdstofs33
schneider-electricofs_test_client_tlxcdsuofs33
schneider-electricopc_factory_server
schneider_electrictlxcdlfofs33
schneider_electrictlxcdltofs33
schneider_electrictlxcdluofs33
schneider_electrictlxcdstofs33
schneider_electrictlxcdsuofs33
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.