First published: Thu Mar 09 2023(Updated: )
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute arbitrary code in the context of the current process.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Hornerautomation Cscape Envision Rv | =4.60 | |
Horner Automation Cscape Envision RV | =4.60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0623 is a vulnerability in Cscape Envision RV version 4.60 that allows an attacker to write data beyond the allocated structures when parsing project files.
CVE-2023-0623 has a severity rating of 7.8, which is considered high.
CVE-2023-0623 affects Cscape Envision RV version 4.60, allowing an attacker to perform an out-of-bounds write vulnerability.
At the moment, there is no fix available for CVE-2023-0623. It is recommended to follow the guidance provided by the product vendor or authorities.
You can find more information about CVE-2023-0623 in the advisory published by the Cybersecurity and Infrastructure Security Agency (CISA) at https://www.cisa.gov/news-events/ics-advisories/icsa-23-040-04.