CVE-2014-0789

Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and earlier, TLXCDLUOFS33 3.5 and earlier, TLXCDLTOFS33 3.5 and earlier, and TLXCDLFOFS33 3.5 and earlier allow remote attackers to cause a denial of service via long arguments to unspecified functions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:schneider-electric:opc_factory_server_tlxcdlfofs:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:opc_factory_server_tlxcdltofs:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:opc_factory_server_tlxcdluofs:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:opc_factory_server_tlxcdstofs:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:opc_factory_server_tlxcdsuofs:*:*:*:*:*:*:*:*

History

25 Sep 2025, 18:15

Type Values Removed Values Added
CVSS v2 : 7.8
v3 : unknown
v2 : 5.0
v3 : unknown
CWE CWE-122
References
  • () http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cybersecurity.page -
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-14-093-01 -

21 Nov 2024, 02:02

Type Values Removed Values Added
References () http://ics-cert.us-cert.gov/advisories/ICSA-14-093-01 - US Government Resource () http://ics-cert.us-cert.gov/advisories/ICSA-14-093-01 - US Government Resource
References () http://www.schneider-electric.com/corporate/en/support/cybersecurity/viewer-news.page?c_filepath=/templatedata/Content/News/data/en/local/cybersecurity/general_information/2014/03/20140325_vulnerability_disclosure_opc_factory_server.xml - Vendor Advisory () http://www.schneider-electric.com/corporate/en/support/cybersecurity/viewer-news.page?c_filepath=/templatedata/Content/News/data/en/local/cybersecurity/general_information/2014/03/20140325_vulnerability_disclosure_opc_factory_server.xml - Vendor Advisory

Information

Published : 2014-04-04 15:09

Updated : 2025-09-25 18:15


NVD link : CVE-2014-0789

Mitre link : CVE-2014-0789

CVE.ORG link : CVE-2014-0789


JSON object : View

Products Affected

schneider-electric

  • opc_factory_server_tlxcdluofs
  • opc_factory_server_tlxcdlfofs
  • opc_factory_server_tlxcdstofs
  • opc_factory_server_tlxcdltofs
  • opc_factory_server_tlxcdsuofs
CWE
CWE-122

Heap-based Buffer Overflow

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer