Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42285 | Stack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier may cause a denial-of-service (DoS) condition, arbitrary code execution, and/or information disclosure because the issues exist in parsing of KPP project files. |
Tue, 15 Oct 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jtekt kostac Plc
|
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:jtekt:kostac_plc:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jtekt kostac Plc
|
Thu, 03 Oct 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jtekt
Jtekt kostac Plc Programming Software |
|
| CPEs | cpe:2.3:a:jtekt:kostac_plc_programming_software:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jtekt
Jtekt kostac Plc Programming Software |
|
| Metrics |
ssvc
|
Thu, 03 Oct 2024 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier may cause a denial-of-service (DoS) condition, arbitrary code execution, and/or information disclosure because the issues exist in parsing of KPP project files. | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-10-03T15:32:41.172Z
Reserved: 2024-09-18T23:29:17.957Z
Link: CVE-2024-47135
Updated: 2024-10-03T15:32:33.979Z
Status : Analyzed
Published: 2024-10-03T03:15:02.697
Modified: 2024-10-15T18:21:04.813
Link: CVE-2024-47135
No data.
OpenCVE Enrichment
No data.
EUVD