CVE-2014-0774

medium
Published 2014-02-28 · Modified 2026-04-29
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-031-01

Application impact

VendorProductVersionsFixed
schneider-electricofs_test_client_tlxcdlfofs333.35
schneider-electricofs_test_client_tlxcdltofs333.35
schneider-electricofs_test_client_tlxcdluofs333.35
schneider-electricofs_test_client_tlxcdstofs333.35
schneider-electricofs_test_client_tlxcdsuofs333.35
schneider-electricopc_factory_server3.35

References

CWEs

CWE-121 CWE-119

Verify integrity in audit chain (admin only). AS-IS.