PT-2024-12595 · Loftware · Loftware Spectrum

Nikolas Sotiriu

·

Published

2024-09-10

·

Updated

2025-05-29

·

CVE-2023-37227

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Loftware Spectrum versions prior to 4.6 HF13
Description The issue is related to the deserialization of untrusted data. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For versions prior to 4.6 HF13, update to version 4.6 HF13 or later to resolve the issue. As a temporary workaround, consider restricting the deserialization of untrusted data until a patch is applied.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2023-37227

Affected Products

Loftware Spectrum