CVE-2014-0780 Details
Description
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.
A directory traversal vulnerability has been identified in the NTWebServer component of InduSoft Web Studio version 7.1 prior to Service Pack 2 Patch 4. This vulnerability allows remote attackers to read administrative passwords stored in APP files by sending unspecified web requests. The extracted passwords could then be used to execute arbitrary code on the server.
Users can upgrade to InduSoft Web Studio version 7.1 Service Pack 2 Patch 4 to address this vulnerability. The patch is available for download from the InduSoft Update Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0780 | CISA-ADP | US Government Resource |
| http://ics-cert.us-cert.gov/advisories/ICSA-14-107-02 | CVE | PatchThird Party AdvisoryUS Government Resource |
| https://www.exploit-db.com/exploits/42699/ | CVE | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/67056 | CVE | Broken LinkThird Party AdvisoryVDB Entry |
| http://download.indusoft.com/71.2.4/IWS71.2.4.zip | [email protected] | Broken Link |
| https://www.cisa.gov/news-events/ics-advisories/icsa-14-107-02 | [email protected] | US Government Resource |
| https://www.exploit-db.com/exploits/42699/ | [email protected] | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/67056 | [email protected] | Broken LinkThird Party AdvisoryVDB Entry |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| InduSoft Web Studio NTWebServer Directory Traversal Vulnerability | Apr 15, 2022 | May 6, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| indusoft web studio | 7.1 - 7.1 sp1 7.1 sp2 |
CPE
Remediation
| |
Change History
17 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Sep 25, 2025 | CVE Modified | [email protected] |
| Feb 12, 2025 | Modified Analysis | [email protected] |
| Feb 7, 2025 | CVE Modified | CISA-ADP |
| Dec 19, 2024 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 2, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Sep 16, 2017 | CVE Modified | [email protected] |
| Jul 24, 2015 | Modified Analysis | [email protected] |
| Jun 4, 2015 | CVE Modified | [email protected] |
| Apr 25, 2014 | Initial Analysis | [email protected] |