Heap-based Buffer Overflow Vulnerabilities in WECON LeviStudioU
CVE-2019-6539

7.8HIGH

Key Information:

Vendor

Ics-cert

Vendor
CVE Published:
5 February 2019

What is CVE-2019-6539?

Multiple heap-based buffer overflow vulnerabilities have been detected in WECON's LeviStudioU, specifically in versions 1.8.56 and earlier. These vulnerabilities pose a significant security risk as they may permit attackers to execute arbitrary code within the affected software. The findings, reported by researchers Mat Powell, Ziad Badawi, and Natnael Samson from Trend Micro's Zero Day Initiative, underscore the need for organizations using this software to prioritize updates and implement necessary security measures to mitigate potential threats.

Affected Version(s)

WECON LeviStudioU LeviStudioU Versions 1.8.56 and prior

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.