CVE-2014-0780criticalunder attackCWE-22

CVE-2014-0780: critical vulnerability in InduSoft Web Studio

InduSoft Web Studio Path Traversal

Published · Updated

100Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 9.8epss 75%
from disclosure to weapon1237 days
Published on NVDApr 25
1st PoC+1237d
CISA KEV+2912d
exploitation probability
75%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2022-05-06

Apply updates per vendor instructions.

In short

A flaw in InduSoft Web Studio's web server allows attackers to access files outside the intended directory, exposing stored administrative passwords and enabling them to take over the system.

Technical detail

Directory traversal vulnerability in NTWebServer permits unauthenticated remote attackers to bypass path restrictions and read sensitive APP configuration files containing administrative credentials. Successful exploitation allows arbitrary code execution with elevated privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
InduSoft · Web Studio
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.