CVE-2014-0780
KEVmoderateDirectory Traversal in InduSoft Web Studio NTWebServer Enables Password Theft and RCE
CISA: InduSoft Web Studio NTWebServer Directory Traversal Vulnerability
InduSoft Web Studio's bundled NTWebServer component contains a directory traversal flaw (CWE-22) that lets a remote attacker send crafted HTTP requests that escape the web root and read files outside it, including the product's application (APP) files. Because those APP files store administrative passwords, an attacker who harvests them can authenticate to the product and ultimately achieve remote code execution. Any deployment running InduSoft Web Studio with the NTWebServer web service enabled is affected, especially HMI/SCADA servers reachable from untrusted networks or the internet. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-15) and carries a high EPSS score of about 74% (99th percentile), indicating substantial exploitation likelihood, though public PoC code is not known. Ransomware association is not documented.
What to do: Apply updates to InduSoft Web Studio per the vendor's instructions, as required by CISA's KEV listing. Until patched, restrict access to NTWebServer from untrusted networks and review web logs for directory traversal request patterns. If compromise is suspected, rotate administrative passwords stored in APP files, since their disclosure enables remote code execution.
| InduSoft Web Studio | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.
- Affected
- InduSoft Web Studio
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- InduSoft
- Products
- Web Studio
- Weakness
- CWE-22