CVE-2014-0780
CRITICAL KEVIndusoft Web Studio - Path Traversal
Title source: ruleDescription
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.
Exploits (1)
References (6)
Scores
CVSS v3
9.8
EPSS
0.8925
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-04-15
VulnCheck KEV
2022-01-12
InTheWild.io
2022-04-15
ENISA EUVD
EUVD-2014-0811
CWE
CWE-22
Status
published
Products (2)
InduSoft/Web Studio
7.1
indusoft/web_studio
7.1 (3 CPE variants)
Published
Apr 25, 2014
KEV Added
Apr 15, 2022
Tracked Since
Feb 18, 2026