First published: Mon Jan 15 2024(Updated: )
In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, which would result in execution of arbitrary code on affected installations of Cscape.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Horner Automation Cscape | <9.90 | |
Horner Automation Cscape | =9.90 | |
Horner Automation Cscape | =9.90-sp1 | |
Horner Automation Cscape | =9.90-sp10 | |
Horner Automation Cscape | =9.90-sp2 | |
Horner Automation Cscape | =9.90-sp3 | |
Horner Automation Cscape | =9.90-sp4 | |
Horner Automation Cscape | =9.90-sp5 | |
Horner Automation Cscape | =9.90-sp6 | |
Horner Automation Cscape | =9.90-sp7 | |
Horner Automation Cscape | =9.90-sp7.1 | |
Horner Automation Cscape | =9.90-sp8 | |
Horner Automation Cscape | =9.90-sp9 |
Horner Automation recommends users to apply v9.90 SP11 https://hornerautomation.com/cscape-software/ or the latest version of their software.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.