CVE-2014-5407

Summary

Multiple stack-based buffer overflows in Schneider Electric VAMPSET 2.2.136 and earlier allow local users to cause a denial of service (application halt) via a malformed (1) setting file or (2) disturbance recording file.

Affected Software

VendorProductVersion RangeStatus
Schneider ElectricVAMPSET0 <= 2.2.136affected
Schneider ElectricVAMPSET2.2.145unaffected

Weaknesses

  • CWE-121: CWE-121

Workarounds

To protect the computer and configuration files from unauthorized escalation of privileges through manipulation, Schneider Electric recommends users employ best IT practices to secure their computers and relay’s configuration files and to use User Access Control (UAC) to further improve the security of the computer. Additionally, to minimize the risk of attack, users who are not directly using this software on a regular basis are strongly encouraged to delete this application from their computer to reduce the likelihood of attack and to store relay configuration files in the client’s protected location.

ADP Enrichment

CVE Program Container

Additional References

References