{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"InTouch Access Anywhere Server","vendor":"Schneider Electric","versions":[{"status":"affected","version":"10.6"},{"status":"affected","version":"11.0"}]}],"datePublic":"2015-01-08T07:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote attackers to execute arbitrary code via a request for a filename that does not exist.</p>"}],"value":"Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote attackers to execute arbitrary code via a request for a filename that does not exist."}],"metrics":[{"cvssV2_0":{"accessComplexity":"LOW","accessVector":"NETWORK","authentication":"NONE","availabilityImpact":"COMPLETE","baseScore":10,"confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","version":"2.0"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-121","description":"CWE-121","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert","dateUpdated":"2025-07-24T22:42:57.203Z"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000104.pdf"},{"tags":["x_refsource_MISC"],"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-15-008-02"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Schneider Electric has released a security update that mitigates the \nstack-based buffer overflow vulnerability in Wonderware’s InTouch Access\n Anywhere Server product, Versions 10.6 and 11.0. Schneider Electric’s \nsecurity updates for Version 10.6 and Version 11.0 are available at the \nfollowing location with a user account:</p>\n<p><a target=\"_blank\" rel=\"nofollow\" href=\"https://wdnresource.wonderware.com/tracking/confirmdownload.aspx?id=3001&amp;url=https://wdnresource.wonderware.com/support/patchfixes/1/WW-ITAA2014P01-LFSEC104.zip&amp;rme=https://wdnresource.wonderware.com/support/patchfixes/1/WW-ITAA2014P01-LFSEC104.txt\">https://wdnresource.wonderware.com/tracking/confirmdownload.aspx?id=3001&amp;url=https://wdnresource...</a></p>\n<p>Schneider Electric has released a security bulletin titled “InTouch \nAccess Anywhere Server Security Vulnerability, LFSEC00000104” to \nannounce the security update, which is available at the following \nlocation:</p>\n<p><a target=\"_blank\" rel=\"nofollow\" href=\"https://gcsresource.invensys.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000104.pdf\">https://gcsresource.invensys.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000104.pdf</a></p>\n\n<br>"}],"value":"Schneider Electric has released a security update that mitigates the \nstack-based buffer overflow vulnerability in Wonderware’s InTouch Access\n Anywhere Server product, Versions 10.6 and 11.0. Schneider Electric’s \nsecurity updates for Version 10.6 and Version 11.0 are available at the \nfollowing location with a user account:\n\n\n https://wdnresource.wonderware.com/tracking/confirmdownload.aspx?id=3001&url=https://wdnresource... https://wdnresource.wonderware.com/tracking/confirmdownload.aspx \n\n\nSchneider Electric has released a security bulletin titled “InTouch \nAccess Anywhere Server Security Vulnerability, LFSEC00000104” to \nannounce the security update, which is available at the following \nlocation:\n\n\n https://gcsresource.invensys.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000104.pdf"}],"source":{"advisory":"ICSA-15-008-02","discovery":"INTERNAL"},"title":"Schneider Electric Wonderware InTouch Access Anywhere Server Buffer Overflow","x_generator":{"engine":"Vulnogram 0.2.0"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2014-9190","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote attackers to execute arbitrary code via a request for a filename that does not exist."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000104.pdf","refsource":"CONFIRM","url":"https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000104.pdf"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-15-008-02","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-008-02"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-06T13:40:24.643Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://wdnresource.wonderware.com/support/docs/_SecurityBulletins/Security_Bulletin_LFSEC00000104.pdf"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-008-02"}]}]},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2014-9190","datePublished":"2015-01-10T02:00:00.000Z","dateReserved":"2014-12-02T00:00:00.000Z","dateUpdated":"2025-07-24T22:42:57.203Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}