First published: Thu Mar 09 2023(Updated: )
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute arbitrary code in the context of the current process.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Hornerautomation Cscape Envision Rv | =4.60 | |
Horner Automation Cscape Envision RV | =4.60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-0622.
The severity of CVE-2023-0622 is high with a CVSS score of 7.8.
Cscape Envision RV version 4.60 is affected by CVE-2023-0622.
CVE-2023-0622 allows an attacker to write past the end of allocated data structures, potentially causing system crashes or remote code execution.
At the time of writing, there is no known fix or patch available for CVE-2023-0622. It is recommended to follow the recommendations provided by the vendor or security advisories to mitigate the risk.