EXPOSURES › CVE-2014-0780
CVE-2014-0780
HIGH ⌖ ON CISA KEV · EXPLOITEDInduSoft Web Studio NTWebServer suffered a directory traversal flaw allowing attackers to read admin passwords and execute remote code.
The NTWebServer component in InduSoft Web Studio had a directory traversal vulnerability that let remote attackers read administrative passwords from APP files and execute arbitrary code. DIB organizations must ensure all industrial control system (ICS) and OT software are patched against known KEV vulnerabilities, as this flaw was actively exploited in the wild. Failure to patch such components can lead to full system compromise and violate CMMC/NIST 800-171 requirements for patch management and vulnerability mitigation.
Shame score — A directory traversal flaw enabling remote code execution and password theft was actively exploited in the wild, indicating negligent patch management and avoidable exposure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.