PT-2018-18132 · Wecon · Wecon Levistudiou+3

Michael Deplante

+1

·

Published

2018-04-26

·

Updated

2019-10-09

·

CVE-2018-7527

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Wecon LeviStudioU version 1.8.29 Wecon PI Studio HMI Project Programmer, Build: November 11, 2017 and prior LeviStudio HMI Editor, Version 1.10
Description A buffer overflow can be triggered by opening a specially crafted file, potentially leading to remote code execution. The issue affects multiple components of Wecon LeviStudioU, including the DataLogTool, where vulnerabilities in the History Curve Set, INI Parser, and Edit functions can be exploited.
Recommendations For Wecon LeviStudioU version 1.8.29, update to a version that includes a fix for the buffer overflow issue. For Wecon PI Studio HMI Project Programmer, Build: November 11, 2017 and prior, update to a build that includes a fix for the buffer overflow issue. For LeviStudio HMI Editor, Version 1.10, update to a version that includes a fix for the buffer overflow issue. As a temporary workaround, consider avoiding the use of specially crafted files that could trigger the buffer overflow until a patch is available.

Fix

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7527
ZDI-18-406
ZDI-18-407
ZDI-18-408
ZDI-18-409

Affected Products

Datalogtool
Levi Studio Hmi Editor
Wecon Levistudiou
Wecon Pi Studio Hmi Project Programmer