Horner Automation Cscape Out-of-bounds Read
CVE-2023-31278
7.8HIGH
What is CVE-2023-31278?
Horner Automation's Cscape software contains a vulnerability due to a lack of adequate validation of user-supplied data when parsing project files, such as Human-Machine Interface (HMI) files. This weakness could lead to an out-of-bounds read condition, potentially allowing an attacker to exploit this flaw to execute arbitrary code within the context of the current process, posing security risks to the system.
Affected Version(s)
Cscape v9.90 SP8
Cscape EnvisionRV v4.70
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Heinzl reported these vulnerabilities to CISA.
