Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.
2014-02-28T06:18:54.277
2025-09-24T22:15:34.533
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:L/AC:L/Au:S/C:C/I:C/A:C
3.1
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | schneider-electric | ofs_test_client_tlxcdlfofs33 | 3.35 | Yes |
| Application | schneider-electric | ofs_test_client_tlxcdltofs33 | 3.35 | Yes |
| Application | schneider-electric | ofs_test_client_tlxcdluofs33 | 3.35 | Yes |
| Application | schneider-electric | ofs_test_client_tlxcdstofs33 | 3.35 | Yes |
| Application | schneider-electric | ofs_test_client_tlxcdsuofs33 | 3.35 | Yes |
| Application | schneider-electric | opc_factory_server | 3.35 | Yes |