Vulnerability record · CVE-2014-0780 · published 25 April 2014
CVE-2014-0780: InduSoft Web Studio NTWebServer path traversal exposes admin passwords
Indusoft · Web Studio
NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 is vulnerable to directory traversal, allowing remote attackers to read administrative passwords stored in APP files. Because those credentials can then be used to execute arbitrary code, the flaw gives an unauthenticated network attacker a direct path to full control of the affected system.
Description
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, KEV-listed, public exploit available, and EPSS above the 99th percentile make this an urgent, actively targeted flaw.
What it is
NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 is vulnerable to directory traversal, allowing remote attackers to read administrative passwords stored in APP files. Because those credentials can then be used to execute arbitrary code, the flaw gives an unauthenticated network attacker a direct path to full control of the affected system.
Impact
An attacker gains administrative credentials and can execute arbitrary code on the host, effectively taking over the HMI/SCADA server.
Attack surface
Reachable over the network through the NTWebServer web interface; the CVSS vector shows no privileges and no user interaction required, so any host that can reach the service can attempt it.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-04-15, and a public Exploit-DB entry exists; EPSS is 0.73965 (99.455th percentile), indicating high likelihood of exploitation activity.
What to do
- Apply the vendor update for InduSoft Web Studio 7.1 SP2 Patch 4 or later, per the CISA ICS advisory ICSA-14-107-02.
- If patching is not immediately possible, restrict network access to NTWebServer to trusted management hosts only.
- Rotate any administrative passwords stored in APP files, since they may already be exposed.
- Place the HMI/SCADA server behind a firewall or VPN and remove direct internet exposure.
- Monitor the CISA KEV due date (2022-05-06) and confirm remediation status.
Detection
- Search web server logs for traversal sequences such as ../ or encoded variants in requests to NTWebServer.
- Alert on unexpected reads of APP files or other configuration files outside the web root.
- Monitor for authentication attempts or process execution using recovered administrative credentials.
- Review network traffic to the NTWebServer port for anomalous or automated request patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-0780 to the Known Exploited Vulnerabilities catalog on 15 April 2022 as "InduSoft Web Studio NTWebServer Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 6 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://download.indusoft.com/71.2.4/IWS71.2.4.zip | Broken Link |
| http://www.securityfocus.com/bid/67056 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/news-events/ics-advisories/icsa-14-107-02 | US Government Resource |
| https://www.exploit-db.com/exploits/42699/ | ExploitThird Party AdvisoryVDB Entry |
| http://ics-cert.us-cert.gov/advisories/ICSA-14-107-02 | PatchThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/67056 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/42699/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0780 | US Government Resource |
Track CVE-2014-0780 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0780), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.