PT-2021-7368 · Wecon · Wecon Levistudiou

Natnael Samson

+1

·

Published

2021-08-18

·

Updated

2022-02-09

·

CVE-2021-23157

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WECON LeviStudioU versions 2019-09-21 and prior
Description The issue is caused by a heap-based buffer overflow in the dynamic memory of WECON LeviStudioU, which may allow a remote attacker to execute arbitrary code. This can be achieved through the exploitation of the heap-based buffer overflow vulnerability, potentially allowing for remote code execution.
Recommendations For WECON LeviStudioU versions 2019-09-21 and prior, update to a version later than 2019-09-21 to resolve the issue. As a temporary workaround, consider restricting access to the UMP file parsing functionality until a patch is available. Avoid using the ScreenInfo Tag ScrnName and ScrnFile in the UMP file parsing screen until the issue is resolved.

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05812
CVE-2021-23157
ZDI-22-130
ZDI-22-132

Affected Products

Wecon Levistudiou