← Vulnerability feed

Vulnerability record · CVE-2014-0780 · published 25 April 2014

CVE-2014-0780: InduSoft Web Studio NTWebServer path traversal exposes admin passwords

Indusoft · Web Studio

NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 is vulnerable to directory traversal, allowing remote attackers to read administrative passwords stored in APP files. Because those credentials can then be used to execute arbitrary code, the flaw gives an unauthenticated network attacker a direct path to full control of the affected system.

9.8 CVSS 3.1 Critical CISA KEV since 15 Apr 2022 EPSS 75% · top 0.5% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 7.5
75%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, KEV-listed, public exploit available, and EPSS above the 99th percentile make this an urgent, actively targeted flaw.

What it is

NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 is vulnerable to directory traversal, allowing remote attackers to read administrative passwords stored in APP files. Because those credentials can then be used to execute arbitrary code, the flaw gives an unauthenticated network attacker a direct path to full control of the affected system.

Impact

An attacker gains administrative credentials and can execute arbitrary code on the host, effectively taking over the HMI/SCADA server.

Attack surface

Reachable over the network through the NTWebServer web interface; the CVSS vector shows no privileges and no user interaction required, so any host that can reach the service can attempt it.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2022-04-15, and a public Exploit-DB entry exists; EPSS is 0.73965 (99.455th percentile), indicating high likelihood of exploitation activity.

What to do

  • Apply the vendor update for InduSoft Web Studio 7.1 SP2 Patch 4 or later, per the CISA ICS advisory ICSA-14-107-02.
  • If patching is not immediately possible, restrict network access to NTWebServer to trusted management hosts only.
  • Rotate any administrative passwords stored in APP files, since they may already be exposed.
  • Place the HMI/SCADA server behind a firewall or VPN and remove direct internet exposure.
  • Monitor the CISA KEV due date (2022-05-06) and confirm remediation status.

Detection

  • Search web server logs for traversal sequences such as ../ or encoded variants in requests to NTWebServer.
  • Alert on unexpected reads of APP files or other configuration files outside the web root.
  • Monitor for authentication attempts or process execution using recovered administrative credentials.
  • Review network traffic to the NTWebServer port for anomalous or automated request patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2014-0780 to the Known Exploited Vulnerabilities catalog on 15 April 2022 as "InduSoft Web Studio NTWebServer Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 6 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://download.indusoft.com/71.2.4/IWS71.2.4.zip Broken Link
http://www.securityfocus.com/bid/67056 Broken LinkThird Party AdvisoryVDB Entry
https://www.cisa.gov/news-events/ics-advisories/icsa-14-107-02 US Government Resource
https://www.exploit-db.com/exploits/42699/ ExploitThird Party AdvisoryVDB Entry
http://ics-cert.us-cert.gov/advisories/ICSA-14-107-02 PatchThird Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/67056 Broken LinkThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/42699/ ExploitThird Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0780 US Government Resource

Track CVE-2014-0780 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-4051InduSoft Web Studio CEServer missing authentication allows remote code executionCEServer.exe in the Remote Agent module of InduSoft Web Studio 6.1 and 7.0 does not require authentication. A remote attacker can reach the service a…EPSS 69%analysed10.0CVE-2011-0342Indusoft web studio memory buffer overflow vulnerabilityMultiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01.04 allow…EPSS 5.9%10.0CVE-2011-1900Indusoft web studio path traversal vulnerabilityDirectory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arbitrary c…EPSS 32%10.0CVE-2011-0488Advantech studio memory buffer overflow vulnerabilityStack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft W…EPSS 8.6%9.8CVE-2018-8840Indusoft web studio stack-based buffer overflow vulnerabilityA remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and …EPSS 8.3%9.3CVE-2011-4052Indusoft web studio memory buffer overflow vulnerabilityStack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote att…EPSS 5.7%9.3CVE-2011-0340Advantech studio memory buffer overflow vulnerabilityMultiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distribute…EPSS 32%7.8CVE-2013-1627Advantech studio path traversal vulnerabilityAbsolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attack…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2014-0780), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.