PT-2023-1669 · Unknown · Kostac Plc Programming
Michael Heinzl
·
Published
2023-03-03
·
Updated
2023-03-13
·
CVE-2023-22419
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kostac PLC Programming Software versions 1.6.9.0 and earlier
Description
The issue is related to an out-of-bounds read vulnerability that occurs when processing a comment block in stage information. This can lead to information disclosure and/or arbitrary code execution when opening a specially crafted project file. The vulnerability is caused by the inability to verify the end of data, resulting in an out-of-bounds read.
Recommendations
For versions 1.6.9.0 and earlier, consider avoiding the use of comment blocks in stage information until a patch is available. As a temporary workaround, restrict access to project files from untrusted sources to minimize the risk of exploitation.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kostac Plc Programming