Impact
The vulnerability is a stack-based buffer overflow (CWE‑121) that corrupts the program’s call stack, allowing an attacker to execute arbitrary code on the host running Labcenter Proteus. The resulting loss of confidentiality, integrity, and availability stems from the attacker gaining control of the application and potentially the underlying operating system.
Affected Systems
Labcenter Proteus is affected, but the CVE data does not list specific versions. The vendor explicitly states that upgrading to version 9.2 SPO resolves the issue. Version identification can be found on the Proteus home page or via the Help menu options "About ISIS" or "About ARES."
Risk and Exploitability
The CVSS score of 8.4 signals a high severity vulnerability, while the EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. The flaw is not listed in CISA’s KEV catalog. The attack vector is inferred to involve the delivery of crafted input through simulation interfaces or data import mechanisms, and it may require local or privileged access, though the exact requirements are not explicitly disclosed.
OpenCVE Enrichment