First published: Tue Feb 19 2019(Updated: )
Cscape, 9.80 SP4 and prior. An improper input validation vulnerability may be exploited by processing specially crafted POC files. This may allow an attacker to read confidential information and remotely execute arbitrary code.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Horner Automation Cscape | <9.80 | |
Horner Automation Cscape | =9.80 | |
Horner Automation Cscape | =9.80-sp1 | |
Horner Automation Cscape | =9.80-sp2 | |
Horner Automation Cscape | =9.80-sp3 | |
Horner Automation Cscape | =9.80-sp4 | |
Hornerautomation Cscape | <9.80 | |
Hornerautomation Cscape | =9.80 | |
Hornerautomation Cscape | =9.80-sp1 | |
Hornerautomation Cscape | =9.80-sp2 | |
Hornerautomation Cscape | =9.80-sp3 | |
Hornerautomation Cscape | =9.80-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6555 is an improper input validation vulnerability in Cscape 9.80 SP4 and prior.
CVE-2019-6555 can be exploited by processing specially crafted POC files.
CVE-2019-6555 may allow an attacker to read confidential information and remotely execute arbitrary code.
Cscape versions 9.80 SP4 and prior are affected by CVE-2019-6555.
CVE-2019-6555 has a severity score of 7.8, which is considered high.
Updating to a version newer than 9.80 SP4 of Cscape can fix the vulnerability.
You can find more information about CVE-2019-6555 at the following links: [link1](http://www.securityfocus.com/bid/107087) and [link2](https://ics-cert.us-cert.gov/advisories/ICSA-19-050-03).