First published: Fri Apr 25 2014(Updated: )
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
InduSoft Web Studio | <=7.1 | |
InduSoft Web Studio | =7.1 | |
InduSoft Web Studio | =7.1-sp1 | |
InduSoft Web Studio | ||
InduSoft Web Studio | =7.1-sp2 | |
=7.1 | ||
=7.1-sp1 | ||
=7.1-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0780 has a critical severity rating due to the potential for remote attackers to execute arbitrary code.
To fix CVE-2014-0780, update InduSoft Web Studio to version 7.1 SP2 Patch 4 or later.
Exploiting CVE-2014-0780 can lead to unauthorized access to administrative passwords and execution of arbitrary code.
CVE-2014-0780 affects InduSoft Web Studio versions 7.1 prior to SP2 Patch 4.
CVE-2014-0780 is a remote vulnerability, allowing external attackers to exploit it without physical access.