CVE-2015-1014 - CVE House
Back to Database
Status published High CVE-2015-1014

A successful exploit of these vulnerabilities requires the local user...

Vulnerability Description

A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20 of Vijeo Citect/CitectSCADA.. If the application attempts to open that file, the application could crash or allow the attacker to execute arbitrary code. Schneider Electric recommends vulnerable users upgrade the OFS to V3.5 and install the latest service pack (SP 6 or newer) for their associated version.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-1014

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Schneider Electric

View all reports →

Affected Software

OFS v3.5
Vulnerable Versions:
< v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, < v7.30 of Vijeo Citect/CitectSCADA, < v7.20 of Vijeo Citect/CitectSCADA.

Timeline

Official Publish: March 25th, 2019
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)