Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-8514. NOTE: this may be clarified later based on details provided by researchers.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-9013 Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-8514. NOTE: this may be clarified later based on details provided by researchers.
Fixes

Solution

Schneider Electric has released an updated version of the ProClima software, Version 6.1.7, which mitigates these vulnerabilities. Customers are encouraged to download the new version and update their installations. It is important that customers first uninstall the current version. The new version can be downloaded from Schneider Electric’s web site at the following location: http://www.schneider-electric.com/ww/en/download/document/ProClima_software For further information on these vulnerabilities, please see Schneider Electric’s security notification (SEVD 2014-344-01) at Schneider Electric’s cybersecurity web page: http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cyber-security-vulnerabilities-sorted.page http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cyber-security-vulnerabilities-sorted.page%20


Workaround

No workaround given by the vendor.

History

Thu, 24 Jul 2025 22:45:00 +0000

Type Values Removed Values Added
Title Schneider Electric ProClima Command Injection
Weaknesses CWE-77
References
Metrics cvssV2_0

{'score': 9.0, 'vector': 'AV:N/AC:L/Au:N/C:C/I:P/A:P'}

cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-07-24T22:39:42.287Z

Reserved: 2014-12-02T00:00:00

Link: CVE-2014-9188

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-12-27T15:59:04.887

Modified: 2025-07-24T23:15:24.770

Link: CVE-2014-9188

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.