First published: Mon Nov 13 2017(Updated: )
A Stack-based Buffer Overflow issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 Patch 1 and prior versions, and InTouch Machine Edition v8.0 SP2 Patch 1 and prior versions. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution with high privileges.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
AVEVA InduSoft Web Studio | <=8.0 | |
Wonderware InTouch | <=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14024 is rated as critical due to its potential for remote code execution.
To fix CVE-2017-14024, upgrade to Schneider Electric InduSoft Web Studio v8.0 SP2 Patch 2 or later, and InTouch Machine Edition v8.0 SP2 Patch 2 or later.
CVE-2017-14024 affects Schneider Electric InduSoft Web Studio v8.0 SP2 Patch 1 and prior versions, and InTouch Machine Edition v8.0 SP2 Patch 1 and prior versions.
CVE-2017-14024 is a stack-based buffer overflow vulnerability.
Yes, CVE-2017-14024 can potentially allow remote code execution through exploitation.