Lucene search

K
cveIcscertCVE-2015-1014
HistoryMar 25, 2019 - 7:29 p.m.

CVE-2015-1014

2019-03-2519:29:00
CWE-427
icscert
web.nvd.nist.gov
35
cve-2015-1014
schneider electric
ofs
scada
vijeo citect
citectscada
vulnerability
exploit
dll
upgrade
nvd

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

0.4%

A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20 of Vijeo Citect/CitectSCADA… If the application attempts to open that file, the application could crash or allow the attacker to execute arbitrary code. Schneider Electric recommends vulnerable users upgrade the OFS to V3.5 and install the latest service pack (SP 6 or newer) for their associated version.

Affected configurations

Nvd
Node
schneider-electricopc_factory_serverMatch3.5
AND
schneider-electriccitectscadaMatch7.20
OR
schneider-electriccitectscadaMatch7.30
OR
schneider-electriccitectscadaMatch7.40
OR
schneider-electricscada_expert_vijeo_citectMatch7.20
OR
schneider-electricscada_expert_vijeo_citectMatch7.30
OR
schneider-electricscada_expert_vijeo_citectMatch7.40
VendorProductVersionCPE
schneider-electricopc_factory_server3.5cpe:2.3:a:schneider-electric:opc_factory_server:3.5:*:*:*:*:*:*:*
schneider-electriccitectscada7.20cpe:2.3:a:schneider-electric:citectscada:7.20:*:*:*:*:*:*:*
schneider-electriccitectscada7.30cpe:2.3:a:schneider-electric:citectscada:7.30:*:*:*:*:*:*:*
schneider-electriccitectscada7.40cpe:2.3:a:schneider-electric:citectscada:7.40:*:*:*:*:*:*:*
schneider-electricscada_expert_vijeo_citect7.20cpe:2.3:a:schneider-electric:scada_expert_vijeo_citect:7.20:*:*:*:*:*:*:*
schneider-electricscada_expert_vijeo_citect7.30cpe:2.3:a:schneider-electric:scada_expert_vijeo_citect:7.30:*:*:*:*:*:*:*
schneider-electricscada_expert_vijeo_citect7.40cpe:2.3:a:schneider-electric:scada_expert_vijeo_citect:7.40:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "OFS v3.5",
    "vendor": "Schneider Electric",
    "versions": [
      {
        "status": "affected",
        "version": "< v7.40 of SCADA Expert Vijeo Citect/CitectSCADA"
      },
      {
        "status": "affected",
        "version": "< v7.30 of Vijeo Citect/CitectSCADA"
      },
      {
        "status": "affected",
        "version": "< v7.20 of Vijeo Citect/CitectSCADA."
      }
    ]
  }
]

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

AI Score

7.4

Confidence

High

EPSS

0

Percentile

0.4%

Related for CVE-2015-1014