Skip to main content

CVE detail

CVE-2014-0751

The CIMPLICITY Web-based access component, CimWebServer, does not check the location of shell files being loaded into the system. By modifying the source location, an attacker could send shell code to the CimWebServer which would deploy the nefarious files as part of any SCADA project. This could allow the attacker to execute arbitrary code.

CVSS 6.8 · MediumBuzz score 25.9

Buzz score

Why this CVE is surfacing

Buzz score total 25.9

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 17.9 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
17.9
5 evidence mentions in the snapshot
Diversity score
8.0
3 sources across 1 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
5 source links · newest first
  • Over a dozen vulnerabilities patched by GE in its Cimplicity HMI/SCADA product are reminiscent of ICS attacks conducted by the Russian Sandworm group.

    newswww.securityweek.comJul 19, 2023, 12:28 PM
  • Cryptocurrency miners can pose a serious threat to industrial systems and it’s not uncommon for this type of malware to make its way into operational technology (OT) environments.

    newswww.securityweek.comFeb 13, 2018, 4:21 AM
  • The State of SCADA SecurityCSO Online

    Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems are critical as they are used to monitor and control the delivery of essential services such as electricity, natural gas, water, waste treatment and transportation. But when it comes to securing ICS/SCADA systems, we have some significant challenges to overcome. This week I’ll […]

    newswww.csoonline.comMar 24, 2015, 6:38 PM
  • ICS-CERT (Industrial Control Systems Cyber Emergency Response Team) has issued a warning about an ongoing attack campaign targeting industrial control systems.

    newswww.securityweek.comOct 29, 2014, 5:10 PM
  • The US ICS-CERT has issued a warning about an ongoing sophisticated malware campaign that has hit a number of industrial control systems (ICSs) environments using a variant of the BlackEnergy malware. BlackEnergy started as a DDoS Trojan, but was subsequently turned into a multi-purpose malware kit with modern rootkit/process-injection techniques, strong encryption, support for proxy servers, and data exfiltration capabilities thanks to its modular architecture, which makes it possible for capable programmers to write plug-ins … More →

    newswww.helpnetsecurity.comOct 29, 2014, 5:59 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence