CVE-2014-5407
N/A
Summary
Multiple stack-based buffer overflows in Schneider Electric VAMPSET 2.2.136 and earlier allow local users to cause a denial of service (application halt) via a malformed (1) setting file or (2) disturbance recording file.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Schneider Electric | VAMPSET | 0 <= 2.2.136 | affected |
| Schneider Electric | VAMPSET | 2.2.145 | unaffected |
Weaknesses
- CWE-121: CWE-121
Workarounds
To protect the computer and configuration files from unauthorized escalation of privileges through manipulation, Schneider Electric recommends users employ best IT practices to secure their computers and relay’s configuration files and to use User Access Control (UAC) to further improve the security of the computer. Additionally, to minimize the risk of attack, users who are not directly using this software on a regular basis are strongly encouraged to delete this application from their computer to reduce the likelihood of attack and to store relay configuration files in the client’s protected location.
ADP Enrichment
CVE Program Container
Additional References
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-254-01
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2014/icsa-14-254-01.json
- http://www.schneider-electric.com/products/ww/en/2300-ied-user-software/2320-vamp-user-software/62050-vamp-software/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.