Skip to content
COOEY

EXPOSURES › CVE-2014-0780

CVE-2014-0780

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2014-0780 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

InduSoft Web Studio NTWebServer suffered a directory traversal flaw allowing attackers to read admin passwords and execute remote code.

The NTWebServer component in InduSoft Web Studio had a directory traversal vulnerability that let remote attackers read administrative passwords from APP files and execute arbitrary code. DIB organizations must ensure all industrial control system (ICS) and OT software are patched against known KEV vulnerabilities, as this flaw was actively exploited in the wild. Failure to patch such components can lead to full system compromise and violate CMMC/NIST 800-171 requirements for patch management and vulnerability mitigation.

Shame score — A directory traversal flaw enabling remote code execution and password theft was actively exploited in the wild, indicating negligent patch management and avoidable exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.