Description
The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code.
Published: 2026-07-07
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow (CWE‑121) that corrupts the program’s call stack, allowing an attacker to execute arbitrary code on the host running Labcenter Proteus. The resulting loss of confidentiality, integrity, and availability stems from the attacker gaining control of the application and potentially the underlying operating system.

Affected Systems

Labcenter Proteus is affected, but the CVE data does not list specific versions. The vendor explicitly states that upgrading to version 9.2 SPO resolves the issue. Version identification can be found on the Proteus home page or via the Help menu options "About ISIS" or "About ARES."

Risk and Exploitability

The CVSS score of 8.4 signals a high severity vulnerability, while the EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. The flaw is not listed in CISA’s KEV catalog. The attack vector is inferred to involve the delivery of crafted input through simulation interfaces or data import mechanisms, and it may require local or privileged access, though the exact requirements are not explicitly disclosed.

Generated by OpenCVE AI on July 26, 2026 at 18:51 UTC.

Remediation

Vendor Solution

Labcenter recommends ensuring you are using the latest version (9.2 SPO) of the software. Version can be found by looking at the bottom left of the Proteus home page (Version 8 or higher) or by selecting the About ISIS or About ARES option from the Help menu. Update notifications appear in the new and information section of the home page where you can activate the download and installation directly. If you have questions or need help please contact Labcenter or your local distributor.


OpenCVE Recommended Actions

  • Upgrade Labcenter Proteus to version 9.2 SPO or later, as recommended by the vendor.
  • Until the upgrade, restrict the handling of external data by disabling or limiting import of simulation files and disabling network interfaces, reducing the chance of a crafted buffer overflow.
  • Apply safe memory handling practices when developing custom plugins or scripts for Proteus, such as using stack canaries or safe string functions, to mitigate stack‑‑121)

Generated by OpenCVE AI on July 26, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Labcenter
Labcenter proteus
Vendors & Products Labcenter
Labcenter proteus

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Description The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code.
Title Stack-Based Buffer Overflow in Labcenter Proteus
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Labcenter Proteus
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-08T13:08:40.658Z

Reserved: 2026-06-03T15:40:50.740Z

Link: CVE-2026-49033

cve-icon Vulnrichment

Updated: 2026-07-08T13:08:21.533Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:00:02Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow