PT-2021-4458 · Fatek Automation · Winproladder

Natnael Samson

+2

·

Published

2021-10-14

·

Updated

2021-10-21

·

CVE-2021-38434

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FATEK Automation WinProladder versions 3.30 and prior
Description The issue is related to improper validation of user-supplied data when parsing project files, which could result in an unexpected sign extension. This could allow a remote attacker to execute arbitrary code by having a user open a specially crafted malicious file.
Recommendations For versions 3.30 and prior, update to a version that properly validates user-supplied data to prevent unexpected sign extension and arbitrary code execution. As a temporary workaround, consider restricting the opening of project files from untrusted sources to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05091
CVE-2021-38434
ZDI-21-1168

Affected Products

Winproladder