Horner Automation Cscape Out-of-bounds Write
CVE-2023-32539
7.8HIGH
What is CVE-2023-32539?
Horner Automation's Cscape software is vulnerable due to insufficient validation of user-supplied data during the parsing of project files, particularly in HMI configurations. This flaw can result in an out-of-bounds write condition, potentially allowing attackers to execute arbitrary code within the context of the affected application process. Organizations using Cscape are advised to apply the necessary patches and implement security best practices to mitigate potential risks.
Affected Version(s)
Cscape v9.90 SP8
Cscape EnvisionRV v4.70
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Heinzl reported these vulnerabilities to CISA.
