The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in Cscape!CANPortMigration. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
No analysis available yet.
Vendor Solution
Horner Automation recommends upgrading the following software: * Cscape: Update to v9.90 SP9 https://hornerautomation.com/cscape-software/ * Cscape Envision RV: Update to v4.80 https://hornerautomation.com/product/cscape-envision-rv/
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-36789 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in Cscape!CANPortMigration. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. |
Tue, 07 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-07T18:08:04.567Z
Reserved: 2023-05-09T17:30:31.084Z
Link: CVE-2023-32545
Updated: 2024-08-02T15:18:37.787Z
Status : Modified
Published: 2023-06-06T15:15:09.867
Modified: 2024-11-21T08:03:34.233
Link: CVE-2023-32545
No data.
OpenCVE Enrichment
No data.
EUVD