Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.
2014-02-28T06:18:54.277
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.9 (MEDIUM)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | schneider-electric | ofs_test_client_tlxcdlfofs33 | 3.35 | Yes |
Application | schneider-electric | ofs_test_client_tlxcdltofs33 | 3.35 | Yes |
Application | schneider-electric | ofs_test_client_tlxcdluofs33 | 3.35 | Yes |
Application | schneider-electric | ofs_test_client_tlxcdstofs33 | 3.35 | Yes |
Application | schneider-electric | ofs_test_client_tlxcdsuofs33 | 3.35 | Yes |
Application | schneider-electric | opc_factory_server | 3.35 | Yes |