Impact
An out-of-bounds read occurs in DASYLab when it parses a .DSB file because user-supplied data is not validated correctly. The flaw allows the program to read a few bytes past the end of an allocated heap buffer during file handling. This can expose sensitive data that resides after the buffer in memory, potentially leaking internal state or other confidential information. The weakness is classified as CWE‑125.
Affected Systems
The vulnerability affects all releases of measX DASYLab prior to version 2026.0.0. The product is distributed under the measX brand.
Risk and Exploitability
The flaw carries a CVSS score of 8.5, indicating high severity. Because the attacker must persuade a user to open a specially crafted .DSB file, the attack vector requires user interaction; the vulnerability is not remotely exploitable over a network. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. If a user opens a malicious file, the application could read beyond its buffer and expose sensitive memory contents, but no direct code execution or denial of service is advertised in the current statement.
OpenCVE Enrichment