{"api_version":"1","generated_at":"2026-07-23T04:58:42+00:00","cve":"CVE-2014-0789","urls":{"html":"https://cve.report/CVE-2014-0789","api":"https://cve.report/api/cve/CVE-2014-0789.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-0789","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-0789"},"summary":{"title":"Schneider Electric OPC Factory Server Buffer Overflow","description":"Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and earlier, TLXCDLUOFS33 3.5 and earlier, TLXCDLTOFS33 3.5 and earlier, and TLXCDLFOFS33 3.5 and earlier allow remote attackers to cause a denial of service via long arguments to unspecified functions.","state":"PUBLISHED","assigner":"icscert","published_at":"2014-04-04 15:09:45","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-122","CWE-119","CWE-122 CWE-122"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"}},{"version":"2.0","source":"ics-cert@hq.dhs.gov","type":"Secondary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}},{"version":"2.0","source":"CNA","type":"CVSS","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","data":{"accessComplexity":"LOW","accessVector":"NETWORK","authentication":"NONE","availabilityImpact":"PARTIAL","baseScore":5,"confidentialityImpact":"NONE","integrityImpact":"NONE","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","version":"2.0"}}],"references":[{"url":"http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cybersecurity.page","name":"http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cybersecurity.page","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-093-01","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-093-01","refsource":"ics-cert@hq.dhs.gov","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.schneider-electric.com/corporate/en/support/cybersecurity/viewer-news.page?c_filepath=/templatedata/Content/News/data/en/local/cybersecurity/general_information/2014/03/20140325_vulnerability_disclosure_opc_factory_server.xml","name":"http://www.schneider-electric.com/corporate/en/support/cybersecurity/viewer-news.page?c_filepath=/templatedata/Content/News/data/en/local/cybersecurity/general_information/2014/03/20140325_vulnerability_disclosure_opc_factory_server.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cybersecurity - Schneider Electric","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-093-01","name":"http://ics-cert.us-cert.gov/advisories/ICSA-14-093-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"Schneider Electric OPC Factory Server Buffer Overflow | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-0789","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0789","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Schneider Electric","product":"OPC Factory Server (OFS)","version":"affected TLXCDSUOFS33 – V3.5 custom","platforms":[]},{"source":"CNA","vendor":"Schneider Electric","product":"OPC Factory Server (OFS)","version":"affected TLXCDSTOFS33 – V3.5 custom","platforms":[]},{"source":"CNA","vendor":"Schneider Electric","product":"OPC Factory Server (OFS)","version":"affected TLXCDLUOFS33 – V3.5 custom","platforms":[]},{"source":"CNA","vendor":"Schneider Electric","product":"OPC Factory Server (OFS)","version":"affected TLXCDLTOFS33 – V3.5 custom","platforms":[]},{"source":"CNA","vendor":"Schneider Electric","product":"OPC Factory Server (OFS)","version":"affected TLXCDLFOFS33 – V3.5 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Schneider Electric has developed a patch to resolve this issue. In order to patch the installation in the field, install OFS V3.5SP1, available on Schneider Electric’s web site at the following URL:  http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cybersecurity.page","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Wei Gao, formerly of IXIA","lang":"en"}],"nvd_cpes":[{"cve_year":"2014","cve_id":"789","vulnerable":"1","versionEndIncluding":"3.35","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"schneider-electric","cpe5":"opc_factory_server_tlxcdlfofs","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"789","vulnerable":"1","versionEndIncluding":"3.35","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"schneider-electric","cpe5":"opc_factory_server_tlxcdltofs","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"789","vulnerable":"1","versionEndIncluding":"3.35","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"schneider-electric","cpe5":"opc_factory_server_tlxcdluofs","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"789","vulnerable":"1","versionEndIncluding":"3.35","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"schneider-electric","cpe5":"opc_factory_server_tlxcdstofs","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"789","vulnerable":"1","versionEndIncluding":"3.35","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"schneider-electric","cpe5":"opc_factory_server_tlxcdsuofs","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T09:27:19.528Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-093-01"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.schneider-electric.com/corporate/en/support/cybersecurity/viewer-news.page?c_filepath=/templatedata/Content/News/data/en/local/cybersecurity/general_information/2014/03/20140325_vulnerability_disclosure_opc_factory_server.xml"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"OPC Factory Server (OFS)","vendor":"Schneider Electric","versions":[{"lessThanOrEqual":"TLXCDSUOFS33 – V3.5","status":"affected","version":"0","versionType":"custom"},{"lessThanOrEqual":"TLXCDSTOFS33 – V3.5","status":"affected","version":"0","versionType":"custom"},{"lessThanOrEqual":"TLXCDLUOFS33 – V3.5","status":"affected","version":"0","versionType":"custom"},{"lessThanOrEqual":"TLXCDLTOFS33 – V3.5","status":"affected","version":"0","versionType":"custom"},{"lessThanOrEqual":"TLXCDLFOFS33 – V3.5","status":"affected","version":"0","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Wei Gao, formerly of IXIA"}],"datePublic":"2014-04-03T06:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and earlier, TLXCDLUOFS33 3.5 and earlier, TLXCDLTOFS33 3.5 and earlier, and TLXCDLFOFS33 3.5 and earlier allow remote attackers to cause a denial of service via long arguments to unspecified functions.</p>"}],"value":"Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and earlier, TLXCDLUOFS33 3.5 and earlier, TLXCDLTOFS33 3.5 and earlier, and TLXCDLFOFS33 3.5 and earlier allow remote attackers to cause a denial of service via long arguments to unspecified functions."}],"metrics":[{"cvssV2_0":{"accessComplexity":"LOW","accessVector":"NETWORK","authentication":"NONE","availabilityImpact":"PARTIAL","baseScore":5,"confidentialityImpact":"NONE","integrityImpact":"NONE","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","version":"2.0"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-122","description":"CWE-122","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-09-25T17:45:27.086Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-14-093-01"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.schneider-electric.com/corporate/en/support/cybersecurity/viewer-news.page?c_filepath=/templatedata/Content/News/data/en/local/cybersecurity/general_information/2014/03/20140325_vulnerability_disclosure_opc_factory_server.xml"},{"url":"http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cybersecurity.page"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Schneider Electric has developed a patch to resolve this issue. In order to patch the installation in the field, install OFS V3.5SP1, available on Schneider Electric’s web site at the following URL:&nbsp;<a target=\"_blank\" rel=\"nofollow\" href=\"http://www.schneider-electric.com/download/WW/EN/results/0/0/8336568-OPC-Factory-Server/0/?showAsIframe=true\">http://www.schneider-electric.com/download/WW/EN/results/0/0/8336568-OPC-Factory-Server/0/?showAsIfr...</a></p><p>OFS V3.5SP1 includes a patched version of the OLE2T macro from Microsoft to resolve the issue.</p><p>For more information regarding this issue, please see the security announcements affecting the OPC Factory Server on Schneider Electric’s web site at the following URL:&nbsp;<a target=\"_blank\" rel=\"nofollow\" href=\"http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cybersecurity.page\">http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cybersecurity.page</a></p>\n\n<br>"}],"value":"Schneider Electric has developed a patch to resolve this issue. In order to patch the installation in the field, install OFS V3.5SP1, available on Schneider Electric’s web site at the following URL:  http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cybersecurity.page"}],"source":{"advisory":"ICSA-14-093-01","discovery":"EXTERNAL"},"title":"Schneider Electric OPC Factory Server Buffer Overflow","x_generator":{"engine":"Vulnogram 0.2.0"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2014-0789","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and earlier, TLXCDLUOFS33 3.5 and earlier, TLXCDLTOFS33 3.5 and earlier, and TLXCDLFOFS33 3.5 and earlier allow remote attackers to cause a denial of service via long arguments to unspecified functions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://ics-cert.us-cert.gov/advisories/ICSA-14-093-01","refsource":"MISC","url":"http://ics-cert.us-cert.gov/advisories/ICSA-14-093-01"},{"name":"http://www.schneider-electric.com/corporate/en/support/cybersecurity/viewer-news.page?c_filepath=/templatedata/Content/News/data/en/local/cybersecurity/general_information/2014/03/20140325_vulnerability_disclosure_opc_factory_server.xml","refsource":"CONFIRM","url":"http://www.schneider-electric.com/corporate/en/support/cybersecurity/viewer-news.page?c_filepath=/templatedata/Content/News/data/en/local/cybersecurity/general_information/2014/03/20140325_vulnerability_disclosure_opc_factory_server.xml"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2014-0789","datePublished":"2014-04-04T15:00:00.000Z","dateReserved":"2014-01-02T00:00:00.000Z","dateUpdated":"2025-09-25T17:45:27.086Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-04-04 15:09:45","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-122","CWE-119","CWE-122 CWE-122"],"metrics":{"cvssMetricV2":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:schneider-electric:opc_factory_server_tlxcdlfofs:*:*:*:*:*:*:*:*","versionEndIncluding":"3.35","matchCriteriaId":"58A9B25F-0A42-4E55-8253-086C8110B46B"},{"vulnerable":true,"criteria":"cpe:2.3:h:schneider-electric:opc_factory_server_tlxcdltofs:*:*:*:*:*:*:*:*","versionEndIncluding":"3.35","matchCriteriaId":"EDAB2AC4-BF6E-4F66-808D-395DA09A2953"},{"vulnerable":true,"criteria":"cpe:2.3:h:schneider-electric:opc_factory_server_tlxcdluofs:*:*:*:*:*:*:*:*","versionEndIncluding":"3.35","matchCriteriaId":"BDB23AE4-FE64-4C13-8703-EBF6A419A149"},{"vulnerable":true,"criteria":"cpe:2.3:h:schneider-electric:opc_factory_server_tlxcdstofs:*:*:*:*:*:*:*:*","versionEndIncluding":"3.35","matchCriteriaId":"BE9D2AE1-6047-42C0-9BE5-3DA9C7445F6D"},{"vulnerable":true,"criteria":"cpe:2.3:h:schneider-electric:opc_factory_server_tlxcdsuofs:*:*:*:*:*:*:*:*","versionEndIncluding":"3.35","matchCriteriaId":"FDF237D6-9874-4669-BBB5-5047D3D0AFDA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"789","Ordinal":"1","Title":"Schneider Electric OPC Factory Server Buffer Overflow","CVE":"CVE-2014-0789","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"789","Ordinal":"1","NoteData":"Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and earlier, TLXCDLUOFS33 3.5 and earlier, TLXCDLTOFS33 3.5 and earlier, and TLXCDLFOFS33 3.5 and earlier allow remote attackers to cause a denial of service via long arguments to unspecified functions.","Type":"Description","Title":"Schneider Electric OPC Factory Server Buffer Overflow"},{"CveYear":"2014","CveId":"789","Ordinal":"2","NoteData":"2014-04-04","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"789","Ordinal":"3","NoteData":"2014-04-04","Type":"Other","Title":"Modified"}]}}}