RULE(RULE ID:312652)

Rule General Information
Release Date: 2020-07-14
Rule Name: Schneider Electric ProClima ATX45 SetHtmlFileName Heap Buffer Overflow Vulnerability (CVE-2014-8511)
Severity:
CVE ID:
Rule Protection Details
Description: Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8512.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows
Reference: http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-344-01
https://ics-cert.us-cert.gov/advisories/ICSA-14-350-01
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-344-01