PT-2021-4458 · Fatek Automation · Winproladder
Natnael Samson
+2
·
Published
2021-10-14
·
Updated
2021-10-21
·
CVE-2021-38434
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FATEK Automation WinProladder versions 3.30 and prior
Description
The issue is related to improper validation of user-supplied data when parsing project files, which could result in an unexpected sign extension. This could allow a remote attacker to execute arbitrary code by having a user open a specially crafted malicious file.
Recommendations
For versions 3.30 and prior, update to a version that properly validates user-supplied data to prevent unexpected sign extension and arbitrary code execution.
As a temporary workaround, consider restricting the opening of project files from untrusted sources to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Winproladder