A Heap-based Buffer Overflow vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end of allocated data structures.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-18551 A Heap-based Buffer Overflow vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end of allocated data structures.
Fixes

Solution

LS Electric GMWin 4 has been discontinued and is no longer available for service. LS electric recommends users to use the XGT series https://www.ls-electric.com/products/category/Smart_Automation_Solution/PLC/XGT_Series_-*XGK,_XGI,_XGR*-  as a replacement. For more information, contact LS Electric https://www.ls-electric.com/support .


Workaround

No workaround given by the vendor.

History

Tue, 17 Jun 2025 19:00:00 +0000

Type Values Removed Values Added
Description A Heap-based Buffer Overflow vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end of allocated data structures.
Title Out-of-bounds Read in Write in LS Electric GMWin 4
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-06-17T20:41:37.493Z

Reserved: 2025-06-11T15:07:28.496Z

Link: CVE-2025-49850

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-17T19:15:34.830

Modified: 2025-06-17T20:50:23.507

Link: CVE-2025-49850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.