Back

MEDIUM

Schneider Electric OFS Stack Buffer Overflow

Published Feb 28, 2014

Description

Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.

Affected products

Remediation

Vendor solution

Schneider Electric has a product upgrade as well as a workaround solution that mitigates this vulnerability. 

Schneider Electric Security Notification SEVD 2014-031-01,”Vulnerability Disclosure – OPC Factory Server V3.35,” http://www.downloads.schneider-electric.com/?p_Conf=&p_localesFilter=&p_docTypeFilter=155589... http://www.downloads.schneider-electric.com/    

The security announcements affecting the OPC Factory Server are available here:

http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cybersecurity.page

Schneider Electric recommends customers to upgrade to OFS v3.4 or later (Version v3.5 is currently available). Customers that cannot upgrade are directed to remove the demonstration client from affected computers, provided it is not required for operations.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Feb 28, 2014
Updated Sep 24, 2025
Reserved Jan 2, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a