Hornerautomation

Cscape

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 17.04.2026 15:14:06
  • Zuletzt bearbeitet 20.04.2026 16:16:50

An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiters makes brute force password enumeration possible.

  • EPSS 0.1%
  • Veröffentlicht 08.05.2025 17:45:03
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Horner Automation Cscape version 10.0 (10.0.415.2) SP1 is vulnerable to an out-of-bounds read vulnerability that could allow an attacker to disclose information and execute arbitrary code on affected installations of Cscape.

  • EPSS 0.08%
  • Veröffentlicht 13.12.2024 01:15:11
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose information and execute arbitrary code.

  • EPSS 0.08%
  • Veröffentlicht 13.12.2024 01:15:05
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supplied data, which could allow reading past the end of allocated data structures, resulting in execution of arbitrary code.

  • EPSS 0.04%
  • Veröffentlicht 15.01.2024 23:15:07
  • Zuletzt bearbeitet 21.11.2024 08:45:30

In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, which would result in execution of arbitrary code on affected installations of Cscape.

  • EPSS 0.05%
  • Veröffentlicht 06.06.2023 17:15:15
  • Zuletzt bearbeitet 21.11.2024 08:02:53

Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds write at CScape_EnvisionRV+0x2e374b. An attacker could leverage this vulnerability to execute arbitrary...

  • EPSS 0.07%
  • Veröffentlicht 06.06.2023 17:15:14
  • Zuletzt bearbeitet 21.11.2024 08:01:43

Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the contex...

  • EPSS 0.05%
  • Veröffentlicht 06.06.2023 17:15:14
  • Zuletzt bearbeitet 21.11.2024 08:01:41

The affected product does not properly validate user-supplied data. If a user opens a maliciously formed CSP file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer. ...

  • EPSS 0.07%
  • Veröffentlicht 06.06.2023 17:15:13
  • Zuletzt bearbeitet 21.11.2024 07:57:11

The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the con...

  • EPSS 0.06%
  • Veröffentlicht 06.06.2023 17:15:13
  • Zuletzt bearbeitet 21.11.2024 07:55:44

The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a use-after-free vulnerability. An attacker could leverage this vulnerability to execute arbitrary code...