First published: Mon Jul 15 2019(Updated: )
A Use After Free: CWE-416 vulnerability exists in Zelio Soft 2, V5.2 and earlier, which could cause remote code execution when opening a specially crafted Zelio Soft 2 project file.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Zelio Soft 2 | <=5.2 | |
Schneider Electric Zelio Soft 2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6822 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Schneider Electric ZelioSoft 2.
The severity of CVE-2019-6822 is high with a severity value of 7.8.
CVE-2019-6822 works by exploiting a use-after-free vulnerability in the file parsing functionality of Schneider Electric ZelioSoft 2.
Affected installations include Schneider Electric ZelioSoft 2 up to version 5.2.
To mitigate CVE-2019-6822, it is recommended to update Schneider Electric ZelioSoft 2 to a version that has the vulnerability patched.