The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.
No analysis available yet.
Vendor Solution
Weintek recommends users to implement the following mitigation techniques:· Upgrade EasyBuilder Pro to v6.07.02.480 https://dl.weintek.com/EBPro/Installer/EBproV60702480.zip , v6.08.01.350 https://dl.weintek.com/EBPro/Installer/EBproV60801350.zip or later. · Use Decompile only on trusted sources and only when needed.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12202 | The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data. |
| Link | Providers |
|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-23-045-01 |
|
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:55:59.469Z
Reserved: 2023-01-06T18:50:05.156Z
Link: CVE-2023-0104
Updated: 2024-08-02T05:02:43.504Z
Status : Modified
Published: 2023-02-22T21:15:11.207
Modified: 2024-11-21T07:36:33.640
Link: CVE-2023-0104
No data.
OpenCVE Enrichment
No data.
EUVD