CVE-2017-14854
Description
A stack buffer overflow in Orpak SiteOmat CGI components prior to version 6.4.414.122 allows remote unauthenticated attackers to execute arbitrary code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stack buffer overflow in Orpak SiteOmat CGI components prior to version 6.4.414.122 allows remote unauthenticated attackers to execute arbitrary code.
Vulnerability
A stack-based buffer overflow vulnerability exists in one of the Orpak SiteOmat CGI components [1]. The affected product is SiteOmat software used for fuel station management. All versions prior to 6.4.414.122 are vulnerable to this overflow (CVE-2017-14854) [1]. The specific CGI endpoint and input parameter triggering the overflow are not detailed in the available references.
Exploitation
This vulnerability is remotely exploitable with low skill level required, and public exploits are available [1]. The attacker needs no authentication or user interaction to trigger the overflow via network access to the affected CGI component [1]. The CVSS v3 vector string (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) confirms network-based exploitation with low attack complexity and no privileges required [1].
Impact
Successful exploitation results in arbitrary remote code execution, which could lead to denial-of-service conditions and unauthorized access to view and edit monitoring, configuration, and payment information [1]. The attacker can achieve full compromise of confidentiality, integrity, and availability (CIA) of the affected system, with no scope change [1].
Mitigation
Orpak (acquired by Gilbarco Veeder-Root) released version 6.4.414.122 to address this vulnerability [1]. Users should upgrade to version 6.4.414.122 or later [1]. The advisory notes that version 6.4.414.084 is also affected but does not specify an exact release date for the fix, only that the vulnerability affects versions prior to 2017-09-25 (as per the CVE description). No workarounds have been publicly documented [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Orpak/Orpak SiteOmat CGIdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
3- www.orpak.comnvdVendor Advisory
- www.securityfocus.com/bid/108167nvdThird Party AdvisoryVDB Entry
- ics-cert.us-cert.gov/advisories/ICSA-19-122-01nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.