Back

HIGH

Schneider Electric Device Type Managers (DTMs) Stack-based Buffer Overflow

Published Feb 1, 2015

Description

Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Library 1.0.2 and earlier, EtherNet/IP Communication Library 1.0.0 and earlier, EM X80 Gateway DTM (MB TCP/SL), Advantys DTM for OTB, Advantys DTM for STB, KINOS DTM, SOLO DTM, and Xantrex DTMs allows remote attackers to execute arbitrary code via unspecified vectors.

Affected products

Remediation

Vendor solution

Schneider Electric has released a patch that resolves the vulnerability by removing the vulnerable DLL. Schneider Electric’s patch is available at the follow location:

http://download.schneider-electric.com/files?p_Doc_Ref=FDT1 DLL Removal Kit.

Schneider Electric’s security notice SEVD-2015-009-01 is available at the following location:

http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2015-009-01

.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Feb 1, 2015
Updated Sep 5, 2025
Reserved Dec 2, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a