CVE-2014-9188: Schneider Electric ProClima Command Injection
Published Dec 27, 2014
·Updated
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-8514. NOTE: this may be clarified later based on details provided by researchers.
Affected Software
1 affected component
Schneider Electric ProClima<=6.0.1
Remediation
Patch Available
Information
Schneider Electric has released an updated version of the ProClima
software, Version 6.1.7, which mitigates these vulnerabilities.
Customers are encouraged to download the new version and update their
installations. It is important that customers first uninstall the
current version. The new version can be downloaded from Schneider
Electric’s web site at the following location:
http://www.schneider-electric.com/ww/en/download/document/ProClima_software
For further information on these vulnerabilities, please see
Schneider Electric’s security notification (SEVD 2014-344-01) at
Schneider Electric’s cybersecurity web page:
http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cyber-security-vulnerabilities-sorted.page http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cyber-security-vulnerabilities-sorted.page%20
Event History
Dec 27, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-9188?
CVE-2014-9188 has a high severity level due to the potential for remote code execution.
2
How do I fix CVE-2014-9188?
To fix CVE-2014-9188, upgrade to Schneider Electric ProClima version 6.1.7 or later.
3
What software is affected by CVE-2014-9188?
CVE-2014-9188 affects Schneider Electric ProClima versions prior to 6.1.7.
4
What type of vulnerability is CVE-2014-9188?
CVE-2014-9188 is identified as a buffer overflow vulnerability.
5
Can CVE-2014-9188 be exploited remotely?
Yes, CVE-2014-9188 can be exploited remotely by attackers to execute arbitrary code.