PT-2021-9463 · M&M · Fdtcontainer

Published

2021-01-22

·

Updated

2022-02-10

·

CVE-2020-12525

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions M&M Software fdtCONTAINER Component versions below 3.5.20304.x M&M Software fdtCONTAINER Component versions 3.6 through 3.6.20304.x
Description The issue is related to the deserialization of untrusted data in the project storage of the M&M Software fdtCONTAINER Component.
Recommendations For versions below 3.5.20304.x, update to version 3.5.20304.x or later. For versions between 3.6 and 3.6.20304.x, update to version 3.6.20304.x or later.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12525

Affected Products

Fdtcontainer