Out-of-Bounds Read Vulnerability in Eaton HMiSoft VU3 Software
CVE-2020-10637
5.5MEDIUM
Summary
An out-of-bounds read vulnerability has been identified in Eaton HMiSoft VU3 software versions up to 3.00.23. This vulnerability can be triggered by a specially crafted input file when loaded by the affected product, potentially allowing unauthorized access to sensitive information. It is essential for users of HMiSoft VU3 to ensure that they are running the latest versions to mitigate risks associated with this vulnerability.
Affected Version(s)
Eaton HMiSoft VU3 (HMIVU3 runtime not impacted) HMiSoft VU3 Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved