First published: Thu Oct 27 2022(Updated: )
Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by writing outside the memory buffer.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Horner Automation Cscape | <9.90 | |
Horner Automation Cscape | =9.90 | |
Horner Automation Cscape | =9.90-sp1 | |
Horner Automation Cscape | =9.90-sp2 | |
Horner Automation Cscape | =9.90-sp3 | |
Horner Automation Cscape | =9.90-sp4 | |
Horner Automation Cscape | =9.90-sp5 | |
Horner Automation Cscape | =9.90-sp6 | |
Horner Automation Cscape | =9.90-sp7 | |
Horner Automation Cscape Version 9.90 SP 6 and prior | ||
Horner Automation Cscape Version 9.90 SP 7 and prior (CVE-2022-3379 and CVE-2022-3378 only) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3379 is a vulnerability in Horner Automation's Cscape version 9.90 SP7 and prior that allows for the execution of arbitrary code by writing outside the memory buffer.
CVE-2022-3379 allows an attacker to execute arbitrary code within the current process of Horner Automation's Cscape by opening a maliciously formed FNT file.
CVE-2022-3379 has a severity rating of 7.8 (high).
Horner Automation's Cscape version 9.90 SP7 and prior are affected by CVE-2022-3379.
To mitigate CVE-2022-3379, it is recommended to update Horner Automation's Cscape to a version beyond 9.90 SP7.