First published: Thu Oct 04 2018(Updated: )
WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior have a stack-based buffer overflow vulnerability which may allow remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
We-con Pi Studio | <=4.2.34 | |
We-con Pi Studio Hmi | <=4.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14818 has a high severity rating due to its potential for remote code execution.
To remediate CVE-2018-14818, update the affected software to versions 4.2.35 or later for PI Studio and 4.2.10 or later for PI Studio HMI.
CVE-2018-14818 can allow an attacker to execute arbitrary code on the affected systems, leading to a complete compromise.
CVE-2018-14818 affects PI Studio versions 4.2.34 and earlier, and PI Studio HMI versions 4.1.9 and earlier.
There are no known workarounds for CVE-2018-14818, so it is essential to apply the available patches.