Junglewise Threat Intelligence

CVE-2014-0780: InduSoft Web Studio NTWebServer Directory Traversal Vulnerability

CVE-2014-0780 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-15

Executive brief

A directory traversal vulnerability in the NTWebServer component of InduSoft Web Studio allows remote attackers to read administrative passwords within APP files. This exposure can be leveraged to achieve remote code execution via unspecified web requests.

Affected products

  • InduSoft Web Studio 7.1 before SP2 Patch 4

Timeline

  • 2014-04-25: disclosed: Initial NVD publication date
  • 2014-04-25: advisory: Initial CVE analysis by ICS-CERT
  • 2022-04-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-15: exploited: Confirmed as exploited in the wild per CISA KEV entry