CVE-2014-8511
published 2014-12-27CVE-2014-8511: Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.44%
90.3th percentile
Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8512. NOTE: this may be clarified later based on details provided by researchers.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | proclima | <= 6.0.1 | — |
| schneider_electric | proclima | <= 6.0.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric ProClima Command Injection Vulnerabilities
cisa_ics·2018-09-05
Schneider Electric ProClima Command Injection Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric ProClima Command Injection Vulnerabilities
Last RevisedSeptember 05, 2018
Alert CodeICSA-14-350-01
## OVERVIEW
NCCIC/ICS-CERT received a report from HP’s Zero Day Initiative (ZDI) concerning command injection vulnerabilities in Schneider Electric’s ProClima software package. These vulnerabilities were reported to ZDI by security researchers Ariele Caltabiano, Andrea Micalizzi, and Brian Gorenc. Schneider Electric has produced an update version that mitigates these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
The f
GHSA
GHSA-gcqr-pxrf-6rrv: Buffer overflow in an ActiveX control in Atx45
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2014-8512 [CRITICAL] CWE-119 GHSA-gcqr-pxrf-6rrv: Buffer overflow in an ActiveX control in Atx45
Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8511. NOTE: this may be clarified later based on details provided by researchers.
GHSA
GHSA-gr4q-vpmv-cwrr: Buffer overflow in an ActiveX control in Atx45
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2014-8511 [HIGH] CWE-119 GHSA-gr4q-vpmv-cwrr: Buffer overflow in an ActiveX control in Atx45
Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8512. NOTE: this may be clarified later based on details provided by researchers.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-12-27
Published