Buffer Overflow Vulnerability in Eaton HMiSoft Software
CVE-2020-10639
7.8HIGH
Summary
A buffer overflow vulnerability exists in Eaton's HMiSoft software for HMiVu3, where a specially crafted input file can exploit this weakness, potentially leading to arbitrary code execution. While the HMIVU3 runtime itself is not affected, versions 3.00.23 and earlier remain vulnerable. This flaw could allow attackers to manipulate the application's memory, causing unstable behavior or unauthorized access.
Affected Version(s)
Eaton HMiSoft VU3 (HMIVU3 runtime not impacted) HMiSoft VU3 Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved