Schneider Electric Wonderware InTouch Access Anywhere Server Buffer Overflow
Summary
| CVE | CVE-2014-9190 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-01-10 02:59:33 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote attackers to execute arbitrary code via a request for a filename that does not exist. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: CWE-121 | CWE-119 | CWE-121 CWE-121
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C | |
| 2.0 | [email protected] | Secondary | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C | |
| 2.0 | CNA | CVSS | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
CVSS v2.0 Breakdown
AV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Schneider-electric | Wonderware Intouch Access Anywhere Server | 10.6 | All | All | All |
| Application | Schneider-electric | Wonderware Intouch Access Anywhere Server | 11.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Schneider Electric | InTouch Access Anywhere Server | affected 10.6 | Not specified |
| CNA | Schneider Electric | InTouch Access Anywhere Server | affected 11.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/news-events/ics-advisories/icsa-15-008-02 | [email protected] | www.cisa.gov | |
| Sign In | af854a3a-2127-422b-91ae-364da2661108 | wdnresource.wonderware.com | |
| Schneider Electric Wonderware InTouch Access Anywhere Server Buffer Overflow Vulnerability | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
Solutions
CNA: Schneider Electric has released a security update that mitigates the stack-based buffer overflow vulnerability in Wonderware’s InTouch Access Anywhere Server product, Versions 10.6 and 11.0. Schneider Electric’s security updates for Version 10.6 and Version 11.0 are available at the following location with a user account: https://wdnresource.wonderware.com/tracking/confirmdownload.aspx?id=3001&url=https://wdnresource... https://wdnresource.wonderware.com/tracking/confirmdownload.aspx Schneider Electric has released a security bulletin titled “InTouch Access Anywhere Server Security Vulnerability, LFSEC00000104” to announce the security update, which is available at the following location: https://gcsresource.invensys.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000104.pdf