Impact
An improper validation of user-supplied data causes an out‑of‑bounds read (CWE‑125) when DASYLab parses a .DSB file. A crafted file can be used to read memory beyond the allocated data structure, potentially leaking sensitive information. The flaw does not provide code execution or denial of service, but it exposes data that may be confidential.
Affected Systems
The vulnerability affects the measX DASYLab product. All versions released before 2026.0.0 are impacted. Users running any of these generations are at risk if they open malicious .DSB files.
Risk and Exploitability
The CVSS base score of 8.6 indicates high impact. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Exploitation requires the victim to open a specially crafted .DSB file, so it is a user‑interactive threat. Attackers must rely on social engineering or malicious distribution of documents to deliver the payload, making the risk moderate to high for exposed environments.
OpenCVE Enrichment