First published: Thu May 26 2022(Updated: )
The affected product is vulnerable to an out-of-bounds write via uninitialized pointer, which may allow an attacker to execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Horner Automation Cscape | <9.90 | |
Horner Automation Cscape | =9.90 | |
Horner Automation Cscape | =9.90-sp1 | |
Horner Automation Cscape | =9.90-sp2 | |
Horner Automation Cscape | =9.90-sp3 | |
Horner Automation Cscape | =9.90-sp4 | |
Horner Automation Cscape | =9.90-sp5 | |
Horner Automation Cscape Csfont: Versions 9.90 SP5 (v9.90.196) and prior |
Horner Automation recommends affected users update to the latest version of Cscape Csfont Version 9.90 SP6.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-28690.
The severity level of CVE-2022-28690 is high.
The affected software for CVE-2022-28690 is Horner Automation Cscape version 9.90 and its service packs 1, 2, 3, 4, and 5.
CVE-2022-28690 is a vulnerability in Horner Automation Cscape that allows an attacker to execute arbitrary code by exploiting an out-of-bounds write via an uninitialized pointer.
To fix CVE-2022-28690, it is recommended to update Horner Automation Cscape to a version that is not vulnerable.