ID

VAR-201404-0549


CVE

CVE-2014-0777


TITLE

IOServer OPC Server of OPC Drivers of Modbus slave/outstation Service disruption in drivers (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2014-001998

DESCRIPTION

The Modbus slave/outstation driver in the OPC Drivers 1.0.20 and earlier in IOServer OPC Server allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted packet. IOServer is a Windows-based OPC server that allows OPC clients such as human-machine interfaces and monitoring and data acquisition systems to exchange factory data with programmable logic circuits. IOServer is prone to an out-of-bounds read vulnerability. OPC Drivers versions prior to 1.0.20 are vulnerable

Trust: 2.79

sources: NVD: CVE-2014-0777 // JVNDB: JVNDB-2014-001998 // CNVD: CNVD-2014-02309 // BID: 66761 // IVD: 7d73dd1f-463f-11e9-8226-000c29342cb1 // IVD: 16c57042-2352-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

category:['ICS']sub_category: -

Trust: 0.4

sources: IVD: 7d73dd1f-463f-11e9-8226-000c29342cb1 // IVD: 16c57042-2352-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-02309

AFFECTED PRODUCTS

vendor:ioservermodel:opc driversscope:lteversion:1.0.20

Trust: 1.8

vendor:ioservermodel:opc serverscope:eqversion: -

Trust: 1.6

vendor:ioservermodel:opc serverscope: - version: -

Trust: 0.8

vendor:ioservermodel:ioserverscope:lteversion:<=1.0.20

Trust: 0.6

vendor:ioservermodel:opc driversscope:eqversion:1.0.20

Trust: 0.6

vendor:ioserver opc servermodel: - scope:eqversion: -

Trust: 0.4

vendor:opc driversmodel: - scope:eqversion:*

Trust: 0.4

sources: IVD: 7d73dd1f-463f-11e9-8226-000c29342cb1 // IVD: 16c57042-2352-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-02309 // CNNVD: CNNVD-201404-159 // JVNDB: JVNDB-2014-001998 // NVD: CVE-2014-0777

CVSS

SEVERITY

CVSSV2

CVSSV3

ics-cert@hq.dhs.gov: CVE-2014-0777
value: HIGH

Trust: 1.0

nvd@nist.gov: CVE-2014-0777
value: HIGH

Trust: 1.0

NVD: CVE-2014-0777
value: HIGH

Trust: 0.8

CNVD: CNVD-2014-02309
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201404-159
value: HIGH

Trust: 0.6

IVD: 7d73dd1f-463f-11e9-8226-000c29342cb1
value: HIGH

Trust: 0.2

IVD: 16c57042-2352-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

nvd@nist.gov: CVE-2014-0777
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

ics-cert@hq.dhs.gov: CVE-2014-0777
severity: HIGH
baseScore: 8.3
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 8.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

CNVD: CNVD-2014-02309
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 7d73dd1f-463f-11e9-8226-000c29342cb1
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

IVD: 16c57042-2352-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 7d73dd1f-463f-11e9-8226-000c29342cb1 // IVD: 16c57042-2352-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-02309 // CNNVD: CNNVD-201404-159 // JVNDB: JVNDB-2014-001998 // NVD: CVE-2014-0777 // NVD: CVE-2014-0777

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.8

problemtype:CWE-125

Trust: 1.0

sources: JVNDB: JVNDB-2014-001998 // NVD: CVE-2014-0777

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201404-159

TYPE

Buffer overflow

Trust: 1.0

sources: IVD: 7d73dd1f-463f-11e9-8226-000c29342cb1 // IVD: 16c57042-2352-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201404-159

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001998

PATCH

title:Top Pageurl:http://www.ioserver.com/

Trust: 0.8

title:IOServer cross-border read vulnerability patchurl:https://www.cnvd.org.cn/patchInfo/show/44826

Trust: 0.6

title:beta2116url:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=49250

Trust: 0.6

sources: CNVD: CNVD-2014-02309 // CNNVD: CNNVD-201404-159 // JVNDB: JVNDB-2014-001998

EXTERNAL IDS

db:NVDid:CVE-2014-0777

Trust: 3.7

db:ICS CERTid:ICSA-14-100-01

Trust: 2.4

db:CNVDid:CNVD-2014-02309

Trust: 1.0

db:CNNVDid:CNNVD-201404-159

Trust: 1.0

db:BIDid:66761

Trust: 0.9

db:JVNDBid:JVNDB-2014-001998

Trust: 0.8

db:IVDid:7D73DD1F-463F-11E9-8226-000C29342CB1

Trust: 0.2

db:IVDid:16C57042-2352-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 7d73dd1f-463f-11e9-8226-000c29342cb1 // IVD: 16c57042-2352-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-02309 // BID: 66761 // CNNVD: CNNVD-201404-159 // JVNDB: JVNDB-2014-001998 // NVD: CVE-2014-0777

REFERENCES

url:http://ics-cert.us-cert.gov/advisories/icsa-14-100-01

Trust: 2.4

url:http://www.ioserver.com/

Trust: 1.0

url:https://www.cisa.gov/news-events/ics-advisories/icsa-14-100-01

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-0777

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-0777

Trust: 0.8

url:http://www.securityfocus.com/bid/66761

Trust: 0.6

sources: CNVD: CNVD-2014-02309 // CNNVD: CNNVD-201404-159 // JVNDB: JVNDB-2014-001998 // NVD: CVE-2014-0777

CREDITS

Chris Sistrunk and Adam Crain

Trust: 0.3

sources: BID: 66761

SOURCES

db:IVDid:7d73dd1f-463f-11e9-8226-000c29342cb1
db:IVDid:16c57042-2352-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2014-02309
db:BIDid:66761
db:CNNVDid:CNNVD-201404-159
db:JVNDBid:JVNDB-2014-001998
db:NVDid:CVE-2014-0777

LAST UPDATE DATE

2025-09-25T23:19:47.104000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-02309date:2014-04-14T00:00:00
db:BIDid:66761date:2014-04-17T01:02:00
db:CNNVDid:CNNVD-201404-159date:2014-04-15T00:00:00
db:JVNDBid:JVNDB-2014-001998date:2014-04-16T00:00:00
db:NVDid:CVE-2014-0777date:2025-09-24T22:15:34.803

SOURCES RELEASE DATE

db:IVDid:7d73dd1f-463f-11e9-8226-000c29342cb1date:2014-04-14T00:00:00
db:IVDid:16c57042-2352-11e6-abef-000c29c66e3ddate:2014-04-14T00:00:00
db:CNVDid:CNVD-2014-02309date:2014-04-14T00:00:00
db:BIDid:66761date:2014-04-10T00:00:00
db:CNNVDid:CNNVD-201404-159date:2014-04-15T00:00:00
db:JVNDBid:JVNDB-2014-001998date:2014-04-16T00:00:00
db:NVDid:CVE-2014-0777date:2014-04-11T16:55:03.457