Cscape (All versions prior to 9.90 SP4) lacks proper validation of user-supplied data when parsing project files. This could lead to memory corruption. An attacker could leverage this vulnerability to execute code in the context of the current process.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-112-01 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2021-04-23T17:27:32
Updated: 2024-08-03T18:51:07.440Z
Reserved: 2021-01-05T00:00:00
Link: CVE-2021-22678
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2021-04-23T18:15:08.233
Modified: 2022-10-24T17:23:09.103
Link: CVE-2021-22678
Redhat
No data.