Impact
An out-of-bounds read occurs in DASYLab when the software processes a user-supplied .DSB file and converts a string, allowing the program to read data past the end of a heap-allocated buffer. This failure of boundary validation can expose sensitive memory contents and is a confidence vulnerability that could be leveraged by a malicious actor to gain confidential information. The vulnerability exploits normal functionality—opening a file—so it does not require special privileges beyond the user action of opening the file.
Affected Systems
The affected product is measX DASYLab. All releases before version 2026.0.0 contain the flaw; any installation of those releases is vulnerable. No other products or versions are mentioned as affected.
Risk and Exploitability
With a CVSS base score of 8.5 the flaw is considered high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV at this time. Exploitation requires user interaction to open a specially crafted .DSB file, which limits the attack vector to social‑engineering scenarios where a user can be convinced to open the file. Because the flaw can lead to confidentiality leakage and requires no network access, the risk to organizations depends on how often users handle untrusted .DSB files and the presence of mitigations such as updated software or file‑level controls.
OpenCVE Enrichment