First published: Fri Feb 25 2022(Updated: )
The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Fatek FvDesigner | <=1.5.100 | |
Fatek Automation FvDesigner | <=1.5.100 | |
Fatek Automation FvDesigner |
FATEK has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of these affected products are invited to contact FATEK customer support for additional information.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21209 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Fatek Automation FvDesigner.
CVE-2022-21209 has a severity value of 7.8 (high).
Yes, user interaction is required to exploit CVE-2022-21209 by visiting a malicious page or opening a malicious file.