CVE-2014-9206
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
14/03/2015
Last modified:
12/04/2025
Description
Stack-based buffer overflow in Device Type Manager (DTM) 3.1.6 and earlier for Schneider Electric Invensys SRD Control Valve Positioner devices 960 and 991 allows local users to gain privileges via a malformed DLL file.
Impact
Base Score 2.0
6.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:schneider-electric:device_type_manager:*:*:*:*:*:*:*:* | 3.1.6 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://download.schneider-electric.com/files?p_File_Id=745435959&p_File_Name=SEVD-2015-050-01.pdf
- https://ics-cert.us-cert.gov/advisories/ICSA-15-055-03
- http://download.schneider-electric.com/files?p_File_Id=745435959&p_File_Name=SEVD-2015-050-01.pdf
- https://ics-cert.us-cert.gov/advisories/ICSA-15-055-03



