7.8
CVE-2022-3379
- EPSS 0.1%
- Published 27.10.2022 23:15:11
- Last modified 21.11.2024 07:19:24
- Source ics-cert@hq.dhs.gov
- Teams watchlist Login
- Open Login
Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by writing outside the memory buffer.
Data is provided by the National Vulnerability Database (NVD)
Hornerautomation ≫ Cscape Version < 9.90
Hornerautomation ≫ Cscape Version9.90 Update-
Hornerautomation ≫ Cscape Version9.90 Updatesp1
Hornerautomation ≫ Cscape Version9.90 Updatesp2
Hornerautomation ≫ Cscape Version9.90 Updatesp3
Hornerautomation ≫ Cscape Version9.90 Updatesp4
Hornerautomation ≫ Cscape Version9.90 Updatesp5
Hornerautomation ≫ Cscape Version9.90 Updatesp6
Hornerautomation ≫ Cscape Version9.90 Updatesp7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.275 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
ics-cert@hq.dhs.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.