Critical severity9.8CISA KEVNVD Advisory· Published Apr 25, 2014· Updated Apr 22, 2026
CVE-2014-0780
CVE-2014-0780
Description
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.
Affected products
3cpe:2.3:a:indusoft:web_studio:7.1:-:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:indusoft:web_studio:7.1:-:*:*:*:*:*:*
- cpe:2.3:a:indusoft:web_studio:7.1:sp1:*:*:*:*:*:*
- cpe:2.3:a:indusoft:web_studio:7.1:sp2:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- ics-cert.us-cert.gov/advisories/ICSA-14-107-02nvdPatchThird Party AdvisoryUS Government Resource
- www.exploit-db.com/exploits/42699/nvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/67056nvdBroken LinkThird Party AdvisoryVDB Entry
- download.indusoft.com/71.2.4/IWS71.2.4.zipnvdBroken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.cisa.gov/news-events/ics-advisories/icsa-14-107-02nvdUS Government Resource
News mentions
0No linked articles in our index yet.