Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote attackers to execute arbitrary code via a request for a filename that does not exist.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-9015 Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote attackers to execute arbitrary code via a request for a filename that does not exist.
Fixes

Solution

Schneider Electric has released a security update that mitigates the stack-based buffer overflow vulnerability in Wonderware’s InTouch Access Anywhere Server product, Versions 10.6 and 11.0. Schneider Electric’s security updates for Version 10.6 and Version 11.0 are available at the following location with a user account: https://wdnresource.wonderware.com/tracking/confirmdownload.aspx?id=3001&url=https://wdnresource... https://wdnresource.wonderware.com/tracking/confirmdownload.aspx Schneider Electric has released a security bulletin titled “InTouch Access Anywhere Server Security Vulnerability, LFSEC00000104” to announce the security update, which is available at the following location: https://gcsresource.invensys.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000104.pdf


Workaround

No workaround given by the vendor.

History

Thu, 24 Jul 2025 22:45:00 +0000

Type Values Removed Values Added
Title Schneider Electric Wonderware InTouch Access Anywhere Server Buffer Overflow
Weaknesses CWE-121
References

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-07-24T22:42:57.203Z

Reserved: 2014-12-02T00:00:00

Link: CVE-2014-9190

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-01-10T02:59:33.693

Modified: 2025-07-24T23:15:25.860

Link: CVE-2014-9190

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.