Description
Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.
Published: 2014-02-28
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Schneider Electric has a product upgrade as well as a workaround solution that mitigates this vulnerability.  Schneider Electric Security Notification SEVD 2014-031-01,”Vulnerability Disclosure – OPC Factory Server V3.35,” http://www.downloads.schneider-electric.com/?p_Conf=&p_localesFilter=&p_docTypeFilter=155589... http://www.downloads.schneider-electric.com/     The security announcements affecting the OPC Factory Server are available here: http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cybersecurity.page Schneider Electric recommends customers to upgrade to OFS v3.4 or later (Version v3.5 is currently available). Customers that cannot upgrade are directed to remove the demonstration client from affected computers, provided it is not required for operations.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2014-0805 Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.
History

Wed, 24 Sep 2025 21:30:00 +0000

Type Values Removed Values Added
Title Schneider Electric OFS Stack Buffer Overflow
Weaknesses CWE-121
References
Metrics cvssV2_0

{'score': 6.9, 'vector': 'AV:L/AC:M/Au:N/C:C/I:C/A:C'}

cvssV2_0

{'score': 6.8, 'vector': 'AV:L/AC:L/Au:S/C:C/I:C/A:C'}


Subscriptions

Schneider-electric Ofs Test Client Tlxcdlfofs33 Ofs Test Client Tlxcdltofs33 Ofs Test Client Tlxcdluofs33 Ofs Test Client Tlxcdstofs33 Ofs Test Client Tlxcdsuofs33 Opc Factory Server
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-09-24T21:10:10.144Z

Reserved: 2014-01-02T00:00:00.000Z

Link: CVE-2014-0774

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-02-28T06:18:54.277

Modified: 2025-09-24T22:15:34.533

Link: CVE-2014-0774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses