First published: Tue Jun 06 2023(Updated: )
The affected product does not properly validate user-supplied data. If a user opens a maliciously formed CSP file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Horner Automation Cscape | =9.90-sp8 | |
Hornerautomation Cscape Envisionrv | =4.70 | |
Horner Automation Cscape: v9.90 SP8 | ||
Horner Automation Cscape EnvisionRV | =4.70 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-31244.
CVE-2023-31244 has a severity rating of 7.8 (high).
The affected product is Horner Automation Cscape version 9.90-sp8 and Hornerautomation Cscape Envisionrv version 4.70.
If a user opens a maliciously formed CSP file, an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer.
Unfortunately, there is no specific fix mentioned in the provided information. It is recommended to follow the guidance provided by the official reference link.