Schneider-electric OPC Factory Server 3.5

CPE Details

Schneider-electric OPC Factory Server 3.5
3.5
2019-04-03
15h19 +00:00
2021-08-13
13h34 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:schneider-electric:opc_factory_server:3.5:*:*:*:*:*:*:*

Informations

Vendor

schneider-electric

Product

opc_factory_server

Version

3.5

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-2161 2023-05-16 04h31 +00:00 A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system when a malicious configuration file is loaded on to the software by a local user. 
5.5
Moyen
CVE-2015-1014 2019-03-25 17h07 +00:00 A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20 of Vijeo Citect/CitectSCADA.. If the application attempts to open that file, the application could crash or allow the attacker to execute arbitrary code. Schneider Electric recommends vulnerable users upgrade the OFS to V3.5 and install the latest service pack (SP 6 or newer) for their associated version.
7.3
Haute
CVE-2013-0662 2014-03-28 18h00 +00:00 Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header.
9.3
CVE-2011-3330 2011-11-04 20h00 +00:00 Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers, to execute arbitrary code via an unspecified system parameter.
7.2