from the lack of proper validation of user-supplied data, which could
allow reading past the end of allocated data structures, resulting in
execution of arbitrary code.
No analysis available yet.
Vendor Solution
Horner Automation recommends users update to Cscape v10 SP1 https://hornerautomation.com/cscape-software-free/cscape-software/ or later.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50685 | The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supplied data, which could allow reading past the end of allocated data structures, resulting in execution of arbitrary code. |
Fri, 13 Dec 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Dec 2024 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supplied data, which could allow reading past the end of allocated data structures, resulting in execution of arbitrary code. | |
| Title | Horner Automation Cscape Out-of-bounds Read | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-12-13T21:14:45.265Z
Reserved: 2024-12-04T21:11:42.412Z
Link: CVE-2024-12212
Updated: 2024-12-13T21:14:39.954Z
Status : Deferred
Published: 2024-12-13T01:15:05.810
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-12212
No data.
OpenCVE Enrichment
No data.
EUVD