First published: Wed Mar 03 2021(Updated: )
An uninitialized pointer may be exploited in Fatek FvDesigner Version 1.5.76 and prior while the application is processing project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Fatek Automation Fv Designer | ||
FvDesigner | <=1.5.76 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22670 is rated with high severity due to the potential for arbitrary code execution.
To fix CVE-2021-22670, update Fatek FvDesigner to version 1.5.77 or later.
CVE-2021-22670 is an uninitialized pointer vulnerability that can be exploited through specially crafted project files.
Users of Fatek FvDesigner version 1.5.76 and prior are affected by CVE-2021-22670.
An attacker can exploit CVE-2021-22670 to execute arbitrary code on systems running the affected software.