First published: Wed Jun 01 2022(Updated: )
The affected product is vulnerable to a heap-based buffer overflow via uninitialized pointer, which may allow an attacker to execute arbitrary code
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Horner Automation Cscape | <9.90 | |
Horner Automation Cscape | =9.90 | |
Horner Automation Cscape | =9.90-sp1 | |
Horner Automation Cscape | =9.90-sp2 | |
Horner Automation Cscape | =9.90-sp3 | |
Horner Automation Cscape | =9.90-sp4 | |
Horner Automation Cscape | =9.90-sp5 | |
Horner Automation Cscape Csfont: Versions 9.90 SP5 (v9.90.196) and prior |
Horner Automation recommends affected users update to the latest version of Cscape Csfont Version 9.90 SP6.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-30540.
The severity of CVE-2022-30540 is high with a severity value of 7.8.
The affected software is Horner Automation Cscape version 9.90.
CVE-2022-30540 is a heap-based buffer overflow vulnerability that occurs due to an uninitialized pointer, allowing an attacker to execute arbitrary code.
Yes, a fix is available for CVE-2022-30540. It is recommended to update to the latest version of Horner Automation Cscape to mitigate the vulnerability.