First published: Wed Mar 27 2019(Updated: )
WECON Technology PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior lacks proper validation of user-supplied data, which may result in a read past the end of an allocated object.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
We-con Pi Studio | <=4.2.34 | |
We-con Pi Studio Hmi | <=4.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14814 has been rated as Medium severity due to potential exposure to read past the end of an allocated object.
To fix CVE-2018-14814, update to versions of We-con Pi Studio HMI greater than 4.1.9 and versions of We-con Pi Studio greater than 4.2.34.
The potential impacts of CVE-2018-14814 include information leakage and possible denial of service due to improper validation of user-supplied data.
CVE-2018-14814 affects We-con Pi Studio HMI versions up to 4.1.9 and We-con Pi Studio versions up to 4.2.34.
Once you patch CVE-2018-14814 by upgrading to the secure versions, the vulnerabilities cannot be reversed; they are effectively mitigated.