cbcvebase.
CVE-2015-1014
published 2019-03-25

CVE-2015-1014: A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric…

PriorityP434high7.3CVSS 3.0
AVLACLPRLUIRSUCHIHAH
EPSS
0.46%
36.6th percentile
A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20 of Vijeo Citect/CitectSCADA.. If the application attempts to open that file, the application could crash or allow the attacker to execute arbitrary code. Schneider Electric recommends vulnerable users upgrade the OFS to V3.5 and install the latest service pack (SP 6 or newer) for their associated version.

Affected

4 ranges
VendorProductVersion rangeFixed in
schneider-electricopc_factory_server
schneider_electricofs_v3.5< v7.40 of SCADA Expert Vijeo Citect/CitectSCADAv7.40 of SCADA Expert Vijeo Citect/CitectSCADA
schneider_electricofs_v3.5< v7.30 of Vijeo Citect/CitectSCADAv7.30 of Vijeo Citect/CitectSCADA
schneider_electricofs_v3.5< v7.20 of Vijeo Citect/CitectSCADA.v7.20 of Vijeo Citect/CitectSCADA.

CVSS provenance

nvdv3.07.3HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.