Description
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
Published: 2026-09-03
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds read occurs in DASYLab when the software processes a user-supplied .DSB file and converts a string, allowing the program to read data past the end of a heap-allocated buffer. This failure of boundary validation can expose sensitive memory contents and is a confidence vulnerability that could be leveraged by a malicious actor to gain confidential information. The vulnerability exploits normal functionality—opening a file—so it does not require special privileges beyond the user action of opening the file.

Affected Systems

The affected product is measX DASYLab. All releases before version 2026.0.0 contain the flaw; any installation of those releases is vulnerable. No other products or versions are mentioned as affected.

Risk and Exploitability

With a CVSS base score of 8.5 the flaw is considered high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV at this time. Exploitation requires user interaction to open a specially crafted .DSB file, which limits the attack vector to social‑engineering scenarios where a user can be convinced to open the file. Because the flaw can lead to confidentiality leakage and requires no network access, the risk to organizations depends on how often users handle untrusted .DSB files and the presence of mitigations such as updated software or file‑level controls.

Generated by OpenCVE AI on September 3, 2026 at 23:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest DASYLab security update (version 2026.0.0 or later) issued by measX.
  • If an upgrade is not immediately possible, quarantine or block the use of unknown or untrusted .DSB files and limit file opening to verified sources.
  • Deploy application or endpoint monitoring to detect anomalous memory access or crashes when processing .DSB files, and investigate any incidents promptly.

Generated by OpenCVE AI on September 3, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
Title Out Of Bounds Read in during string conversionwhen parsing a .DSB file in DASYLab
First Time appeared Measx
Measx dasylab
Weaknesses CWE-125
CPEs cpe:2.3:a:measx:dasylab:*:*:*:*:*:*:*:*
Vendors & Products Measx
Measx dasylab
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-09-03T22:06:34.287Z

Reserved: 2026-07-19T15:12:06.825Z

Link: CVE-2026-64200

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T22:18:10.463

Modified: 2026-09-03T22:18:10.463

Link: CVE-2026-64200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T23:45:04Z

Weaknesses