Description
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
Published: 2026-09-03
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper validation of user-supplied data causes an out‑of‑bounds read (CWE‑125) when DASYLab parses a .DSB file. A crafted file can be used to read memory beyond the allocated data structure, potentially leaking sensitive information. The flaw does not provide code execution or denial of service, but it exposes data that may be confidential.

Affected Systems

The vulnerability affects the measX DASYLab product. All versions released before 2026.0.0 are impacted. Users running any of these generations are at risk if they open malicious .DSB files.

Risk and Exploitability

The CVSS base score of 8.6 indicates high impact. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Exploitation requires the victim to open a specially crafted .DSB file, so it is a user‑interactive threat. Attackers must rely on social engineering or malicious distribution of documents to deliver the payload, making the risk moderate to high for exposed environments.

Generated by OpenCVE AI on September 3, 2026 at 23:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest DASYLab release (2026.0.0 or later) to eliminate the read vulnerability.
  • If a later release is not yet available, contact measX support for an interim patch or guidance.
  • Avoid opening .DSB files from untrusted or unknown sources, and verify file integrity before processing.

Generated by OpenCVE AI on September 3, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
Title Out Of Bounds Read outside the bounds of an allocated data structure when parsing a .DSB file in DASYLab
First Time appeared Measx
Measx dasylab
Weaknesses CWE-125
CPEs cpe:2.3:a:measx:dasylab:*:*:*:*:*:*:*:*
Vendors & Products Measx
Measx dasylab
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-09-03T22:04:43.114Z

Reserved: 2026-07-19T15:12:06.825Z

Link: CVE-2026-64199

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T22:18:10.337

Modified: 2026-09-03T22:18:10.337

Link: CVE-2026-64199

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T23:45:04Z

Weaknesses