CVE-2014-0780: InduSoft Web Studio NTWebServer Directory Traversal Vulnerability
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.
Other sources
InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
InduSoft Web Studio NTWebServerto a version that resolves this vulnerability.Fixed in 7.1+Service Pack 2+ Patch 4Patch InduSoft Web Studio v7.1+Service Pack 2+ Patch 4
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0780?
CVE-2014-0780 has a critical severity rating due to the potential for remote attackers to execute arbitrary code.
How do I fix CVE-2014-0780?
To fix CVE-2014-0780, update InduSoft Web Studio to version 7.1 SP2 Patch 4 or later.
What types of attacks can be carried out exploiting CVE-2014-0780?
Exploiting CVE-2014-0780 can lead to unauthorized access to administrative passwords and execution of arbitrary code.
Which versions of InduSoft Web Studio are affected by CVE-2014-0780?
CVE-2014-0780 affects InduSoft Web Studio versions 7.1 prior to SP2 Patch 4.
Is CVE-2014-0780 a local or remote vulnerability?
CVE-2014-0780 is a remote vulnerability, allowing external attackers to exploit it without physical access.