A Heap-based Buffer Overflow vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end of allocated data structures.
Fixes

Solution

LS Electric GMWin 4 has been discontinued and is no longer available for service. LS electric recommends users to use the XGT series https://www.ls-electric.com/products/category/Smart_Automation_Solution/PLC/XGT_Series_-*XGK,_XGI,_XGR*-  as a replacement. For more information, contact LS Electric https://www.ls-electric.com/support .


Workaround

No workaround given by the vendor.

History

Tue, 17 Jun 2025 19:00:00 +0000

Type Values Removed Values Added
Description A Heap-based Buffer Overflow vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end of allocated data structures.
Title Out-of-bounds Read in Write in LS Electric GMWin 4
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-06-17T20:41:37.493Z

Reserved: 2025-06-11T15:07:28.496Z

Link: CVE-2025-49850

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-17T19:15:34.830

Modified: 2025-06-17T20:50:23.507

Link: CVE-2025-49850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.