First published: Thu Oct 27 2022(Updated: )
Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory read.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Horner Automation Cscape | <9.90 | |
Horner Automation Cscape | =9.90 | |
Horner Automation Cscape | =9.90-sp1 | |
Horner Automation Cscape | =9.90-sp2 | |
Horner Automation Cscape | =9.90-sp3 | |
Horner Automation Cscape | =9.90-sp4 | |
Horner Automation Cscape | =9.90-sp5 | |
Horner Automation Cscape | =9.90-sp6 | |
Horner Automation Cscape Version 9.90 SP 6 and prior | ||
Horner Automation Cscape Version 9.90 SP 7 and prior (CVE-2022-3379 and CVE-2022-3378 only) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3377 is a vulnerability in Horner Automation's Cscape software that could allow an attacker to execute arbitrary code.
CVE-2022-3377 has a severity rating of 7.8, which is considered high.
CVE-2022-3377 occurs when a user opens a malicious FNT file, allowing an attacker to access an uninitialized pointer and execute arbitrary code.
Version 9.90 SP 6 and prior of Horner Automation's Cscape software are affected by CVE-2022-3377.
To fix CVE-2022-3377, users should update to a version of Cscape software that is not affected by the vulnerability.