Schneider Electric OPC Factory Server Buffer Overflow
Summary
| CVE | CVE-2014-0789 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-04-04 15:09:45 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and earlier, TLXCDLUOFS33 3.5 and earlier, TLXCDLTOFS33 3.5 and earlier, and TLXCDLFOFS33 3.5 and earlier allow remote attackers to cause a denial of service via long arguments to unspecified functions. |
Risk And Classification
Primary CVSS: v2.0 7.8 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:C
Problem Types: CWE-122 | CWE-119 | CWE-122 CWE-122
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 7.8 | AV:N/AC:L/Au:N/C:N/I:N/A:C | |
| 2.0 | [email protected] | Secondary | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P | |
| 2.0 | CNA | CVSS | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P |
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Schneider-electric | Opc Factory Server Tlxcdlfofs | All | All | All | All |
| Hardware | Schneider-electric | Opc Factory Server Tlxcdltofs | All | All | All | All |
| Hardware | Schneider-electric | Opc Factory Server Tlxcdluofs | All | All | All | All |
| Hardware | Schneider-electric | Opc Factory Server Tlxcdstofs | All | All | All | All |
| Hardware | Schneider-electric | Opc Factory Server Tlxcdsuofs | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Schneider Electric | OPC Factory Server OFS | affected TLXCDSUOFS33 – V3.5 custom | Not specified |
| CNA | Schneider Electric | OPC Factory Server OFS | affected TLXCDSTOFS33 – V3.5 custom | Not specified |
| CNA | Schneider Electric | OPC Factory Server OFS | affected TLXCDLUOFS33 – V3.5 custom | Not specified |
| CNA | Schneider Electric | OPC Factory Server OFS | affected TLXCDLTOFS33 – V3.5 custom | Not specified |
| CNA | Schneider Electric | OPC Factory Server OFS | affected TLXCDLFOFS33 – V3.5 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cybersecurity.page | [email protected] | www2.schneider-electric.com | |
| www.cisa.gov/news-events/ics-advisories/icsa-14-093-01 | [email protected] | www.cisa.gov | |
| Cybersecurity - Schneider Electric | af854a3a-2127-422b-91ae-364da2661108 | www.schneider-electric.com | Vendor Advisory |
| Schneider Electric OPC Factory Server Buffer Overflow | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Wei Gao, formerly of IXIA (en)
Additional Advisory Data
Solutions
CNA: Schneider Electric has developed a patch to resolve this issue. In order to patch the installation in the field, install OFS V3.5SP1, available on Schneider Electric’s web site at the following URL: http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cybersecurity.page
There are currently no legacy QID mappings associated with this CVE.