First published: Thu Mar 09 2023(Updated: )
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds read vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in reads past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute arbitrary code in the context of the current process.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Hornerautomation Cscape Envision Rv | =4.60 | |
Horner Automation Cscape Envision RV | =4.60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0621 is an out-of-bounds read vulnerability in Cscape Envision RV version 4.60 when parsing project files.
The severity of CVE-2023-0621 is high with a CVSS score of 7.8.
CVE-2023-0621 allows an attacker to read past the end of allocated data structures, potentially leading to unauthorized access or information disclosure.
Currently, there is no information available regarding a fix for CVE-2023-0621. It is recommended to follow the guidance provided by the product vendor or software developer.
You can find more information about CVE-2023-0621 in the advisory published by CISA at https://www.cisa.gov/news-events/ics-advisories/icsa-23-040-04.