PT-2021-14280 · Unknown · Cx-Supervisor
Michael Heinzl
·
Published
2021-10-19
·
Updated
2021-10-22
·
CVE-2021-20836
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
CX-Supervisor versions 4.0.0.13 through 4.0.0.16
Description:
The issue allows an attacker with administrative privileges to cause information disclosure and/or arbitrary code execution by opening a specially crafted SCS project file.
Recommendations:
For versions 4.0.0.13 and 4.0.0.16, avoid opening specially crafted SCS project files until a patch is available.
As a temporary workaround, consider restricting access to SCS project files to minimize the risk of exploitation.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cx-Supervisor