An Out-of-bounds Read vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end of allocated data structures.
Fixes

Solution

LS Electric GMWin 4 has been discontinued and is no longer available for service. LS electric recommends users to use the XGT series https://www.ls-electric.com/products/category/Smart_Automation_Solution/PLC/XGT_Series_-*XGK,_XGI,_XGR*-  as a replacement. For more information, contact LS Electric https://www.ls-electric.com/support .


Workaround

No workaround given by the vendor.

History

Tue, 17 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 17 Jun 2025 19:00:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Read vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end of allocated data structures.
Title Out-of-bounds Read in Write in LS Electric GMWin 4
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-06-17T20:39:03.679Z

Reserved: 2025-06-11T15:07:28.496Z

Link: CVE-2025-49849

cve-icon Vulnrichment

Updated: 2025-06-17T20:38:51.346Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-17T19:15:34.690

Modified: 2025-06-17T20:50:23.507

Link: CVE-2025-49849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.