The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead to an out-of-bounds read in IO_CFG. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Horner Automation recommends upgrading the following software: * Cscape: Update to v9.90 SP9 https://hornerautomation.com/cscape-software/ * Cscape Envision RV: Update to v4.80 https://hornerautomation.com/product/cscape-envision-rv/
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-36543 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead to an out-of-bounds read in IO_CFG. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. |
Tue, 07 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-07T16:33:27.970Z
Reserved: 2023-05-09T17:30:31.077Z
Link: CVE-2023-32289
Updated: 2024-08-02T15:10:24.382Z
Status : Modified
Published: 2023-06-06T16:15:10.073
Modified: 2024-11-21T08:03:02.987
Link: CVE-2023-32289
No data.
OpenCVE Enrichment
No data.
EUVD