This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionRV v4.50.3.1 and prior. The issues result from the lack of proper validation of user-supplied data, which can result in reads and writes past the end of allocated data structures. User interaction is required to exploit this vulnerability as an attacker must trick a valid user to open a malicious HMI project file.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-21-355-02 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2022-03-25T18:02:28.244063Z
Updated: 2024-09-16T18:59:09.556Z
Reserved: 2021-12-16T00:00:00
Link: CVE-2021-44462
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-03-25T19:15:09.370
Modified: 2022-04-04T15:38:59.057
Link: CVE-2021-44462
Redhat
No data.