{"api_version":"1","generated_at":"2026-07-23T06:34:04+00:00","cve":"CVE-2014-9205","urls":{"html":"https://cve.report/CVE-2014-9205","api":"https://cve.report/api/cve/CVE-2014-9205.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-9205","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-9205"},"summary":{"title":"CVE-2014-9205","description":"Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMOTIC stable before 8.2.19 and PROMOTIC development before 8.3.2 allows remote attackers to execute arbitrary code by providing a large amount of data.","state":"PUBLISHED","assigner":"icscert","published_at":"2015-03-29 10:59:02","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-062-01","name":"https://ics-cert.us-cert.gov/advisories/ICSA-15-062-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"MICROSYS PROMOTIC Stack Buffer Overflow | ICS-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.promotic.eu/en/pmdoc/News.htm","name":"http://www.promotic.eu/en/pmdoc/News.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"News in the system PROMOTIC 7","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-091/","name":"http://www.zerodayinitiative.com/advisories/ZDI-15-091/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-9205","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-9205","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"9205","vulnerable":"1","versionEndIncluding":"8.2.18","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsys","cpe5":"promotic","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"stable","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9205","vulnerable":"1","versionEndIncluding":"8.3.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsys","cpe5":"promotic","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"development","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T13:40:24.555Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-062-01"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.promotic.eu/en/pmdoc/News.htm"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-091/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-03-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMOTIC stable before 8.2.19 and PROMOTIC development before 8.3.2 allows remote attackers to execute arbitrary code by providing a large amount of data."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-03-29T02:57:00.000Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"tags":["x_refsource_MISC"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-062-01"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.promotic.eu/en/pmdoc/News.htm"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-091/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2014-9205","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMOTIC stable before 8.2.19 and PROMOTIC development before 8.3.2 allows remote attackers to execute arbitrary code by providing a large amount of data."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-15-062-01","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-062-01"},{"name":"http://www.promotic.eu/en/pmdoc/News.htm","refsource":"CONFIRM","url":"http://www.promotic.eu/en/pmdoc/News.htm"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-15-091/","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-15-091/"}]}}}},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2014-9205","datePublished":"2015-03-29T10:00:00.000Z","dateReserved":"2014-12-02T00:00:00.000Z","dateUpdated":"2024-08-06T13:40:24.555Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-03-29 10:59:02","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsys:promotic:*:*:*:*:stable:*:*:*","versionEndIncluding":"8.2.18","matchCriteriaId":"DFBDE7CA-2C10-41F0-B3CE-E91BF17E1675"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsys:promotic:*:*:*:*:development:*:*:*","versionEndIncluding":"8.3.1","matchCriteriaId":"E116CC94-63C1-4DD7-A8CA-282CA2A2EF29"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"9205","Ordinal":"1","Title":"CVE-2014-9205","CVE":"CVE-2014-9205","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"9205","Ordinal":"1","NoteData":"Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMOTIC stable before 8.2.19 and PROMOTIC development before 8.3.2 allows remote attackers to execute arbitrary code by providing a large amount of data.","Type":"Description","Title":"CVE-2014-9205"},{"CveYear":"2014","CveId":"9205","Ordinal":"2","NoteData":"2015-03-29","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"9205","Ordinal":"3","NoteData":"2015-03-28","Type":"Other","Title":"Modified"}]}}}