M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

Project Subscriptions

Vendors Products
Emerson Subscribe
Rosemount Transmitter Interface Software Subscribe
Pepperl-fuchs Subscribe
Io-link Master 4-eip Subscribe
Io-link Master 4-pnio Subscribe
Io-link Master 8-eip Subscribe
Io-link Master 8-eip-l Subscribe
Io-link Master 8-pnio Subscribe
Io-link Master 8-pnio-l Subscribe
Io-link Master Dr-8-eip Subscribe
Io-link Master Dr-8-eip-p Subscribe
Io-link Master Dr-8-eip-t Subscribe
Io-link Master Dr-8-pnio Subscribe
Io-link Master Dr-8-pnio-p Subscribe
Io-link Master Dr-8-pnio-t Subscribe
Io-link Master Firmware Subscribe
Pactware Subscribe
Dtminspector 3 Subscribe
Fdtcontainer Application Subscribe
Fdtcontainer Component Subscribe
Weidmueller Subscribe
Wi Manager Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-4827 M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
Fixes

Solution

M&M Software provides two updated fdtCONTAINER component trees (3.6.20304.x < 3.7 and >= 3.7) see advisory https://cert.vde.com/en-us/advisories/vde-2020-048 for details.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-16T23:11:43.568Z

Reserved: 2020-04-30T00:00:00

Link: CVE-2020-12525

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-01-22T19:15:12.443

Modified: 2024-11-21T04:59:52.110

Link: CVE-2020-12525

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses