LiveActive security incident?Get immediate response
CVE Record

CVE-2015-1014: A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the sys...

A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20 of Vijeo Citect/CitectSCADA.. If the application attempts to open that file, the application could crash or allow the attacker to execute arbitrary code. Schneider Electric recommends vulnerable users upgrade the OFS to V3.5 and install the latest service pack (SP 6 or newer) for their associated version.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This vulnerability affects certain Schneider Electric OFS deployments tied to Vijeo Citect/CitectSCADA versions. A local attacker who can place or load a crafted DLL in the system directory could crash the application or execute code. The business risk is highest for plants still running these legacy SCADA stacks.

Executive priority

Treat this as a targeted legacy OT risk, not an internet-wide emergency. Prioritize sites where affected SCADA servers remain in production, especially where local administrative controls are weak or patching has lagged.

Technical view

CVE-2015-1014 is mapped to CWE-427 and describes unsafe DLL loading/search behavior in Schneider Electric OFS v3.5 with specified Vijeo Citect/CitectSCADA versions. Exploitation requires local interaction with a crafted DLL in the system directory. Impact may include denial of service or arbitrary code execution.

Likely exposure

Exposure is most likely in industrial control environments running Schneider Electric OFS v3.5 with SCADA Expert Vijeo Citect/CitectSCADA v7.40, Vijeo Citect/CitectSCADA v7.30, or v7.20.

Exploitation context

The provided sources do not show CISA KEV listing or active exploitation. The described attack is local and depends on loading a crafted DLL from the system directory, which limits reach but remains serious on SCADA servers.

Researcher notes

The record lacks CVSS details in the provided bundle. Key facts are affected Schneider Electric OFS/CitectSCADA combinations, CWE-427 classification, local DLL prerequisite, and possible crash or arbitrary code execution. Do not infer remote exploitation.

Mitigation direction

  • Inventory Schneider Electric OFS and Vijeo Citect/CitectSCADA versions in OT environments.
  • Upgrade OFS as recommended by Schneider Electric guidance.
  • Install the latest service pack, SP6 or newer, for the associated version.
  • Restrict local write access to system directories on affected servers.
  • Check current vendor guidance before making production OT changes.

Validation and detection

  • Confirm whether affected OFS v3.5 deployments exist in asset records.
  • Verify associated CitectSCADA or Vijeo Citect/CitectSCADA version numbers.
  • Check whether SP6 or newer is installed for each associated version.
  • Review local access controls for system directories on SCADA servers.
  • Look for unexplained application crashes on affected systems.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-427: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2015-1014 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Schneider ElectricOFS v3.5< v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, < v7.30 of Vijeo Citect/CitectSCADA, < v7.20 of Vijeo Citect/CitectSCADA.Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-427 · source CWE mapping

Uncontrolled Search Path Element

Uncontrolled Search Path Element represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.