First published: Tue Oct 17 2017(Updated: )
A Stack-based Buffer Overflow issue was discovered in WECON LEVI Studio HMI Editor v1.8.1 and prior. Multiple stack-based buffer overflow vulnerabilities have been identified in which the application does not verify string size before copying to memory; the attacker may then be able to crash the application or run arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
We-con Levi Studio Hmi Editor | <=1.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-13999 is rated as high severity due to the potential for remote exploitation and denial of service.
To mitigate CVE-2017-13999, upgrade to a patched version of WECON LEVI Studio HMI Editor beyond v1.8.1.
CVE-2017-13999 can lead to a stack-based buffer overflow, potentially causing application crashes and making the system vulnerable to exploitation.
As of now, there is no public knowledge of active exploitation of CVE-2017-13999, but it remains a significant risk.
CVE-2017-13999 affects all versions of WECON LEVI Studio HMI Editor up to and including v1.8.1.