PT-2020-12261 · Eaton · Eaton Hmisoft Vu3

Nattisamson

·

Published

2020-04-15

·

Updated

2020-04-22

·

CVE-2020-10637

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Eaton HMiSoft VU3 versions 3.00.23 and prior
Description The issue is related to an out-of-bounds read that can occur when a specially crafted input file is loaded by the affected product. This can lead to information disclosure. The HMIVU runtimes are not impacted by this issue.
Recommendations For Eaton HMiSoft VU3 versions 3.00.23 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10637
ZDI-20-490
ZDI-20-491
ZDI-20-492
ZDI-20-493

Affected Products

Eaton Hmisoft Vu3