HIGH🇬🇧 English

CVE-2014-9200

CVSS 7.5v2.0pub. 2015-02-01upd. 2026-05-06

Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Library 1.0.2 and earlier, EtherNet/IP Communication Library 1.0.0 and earlier, EM X80 Gateway DTM (MB TCP/SL), Advantys DTM for OTB, Advantys DTM for STB, KINOS DTM, SOLO DTM, and Xantrex DTMs allows remote attackers to execute arbitrary code via unspecified vectors.

oryginał EN
CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
  • Schneider Electric Somachine

    APP
    Schneider-Electric
    wszystkie wersje
  • Schneider Electric Somove

    APP
    Schneider-Electric
    wszystkie wersje
  • Schneider Electric Somove Lite

    APP
    Schneider-Electric
    wszystkie wersje
  • Schneider Electric Unity Pro

    APP
    Schneider-Electric
    wszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCEMemory
CWE
Referencje

Powiązane podatności

CVE-2020-7487CRITICAL9.8PL ✓ten sam produkt

Niewystarczająca weryfikacja autentyczności danych w sterownikach Schneider Electric Modicon

CVE-2020-7475CRITICAL9.8PL ✓ten sam produkt

Injection (reflective DLL) w produktach Schneider Electric — przesyłanie złośliwego kodu do sterownika

CVE-2017-7574CRITICAL9.8PL ✓ten sam produkt

Hardcoded klucz szyfrowania AES w Schneider Electric SoMachine Basic i Modicon TM221CE16R

CVE-2020-7560HIGH8.6ten sam produkt

A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and U...

CVE-2020-7527HIGH7.8ten sam produkt

Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of ...