PT-2022-6682 · Horner Automation · Cscape
Michael Heinzl
·
Published
2022-10-04
·
Updated
2022-10-31
·
CVE-2022-3379
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Horner Automation's Cscape versions 9.90 SP7 and prior
Description
The issue is related to improper validation of user-supplied data, which can lead to a buffer overflow in memory. This can be exploited if a user opens a maliciously formed FNT file, allowing an attacker to execute arbitrary code within the current process.
Recommendations
For versions 9.90 SP7 and prior, consider avoiding the use of FNT files from untrusted sources until a patch is available. As a temporary workaround, restrict access to the functionality that handles FNT files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cscape