Fiche vulnérabilité
CVE-2021-38426 : faille élevée FATEK Automation WinProladder (CVSS 7.8)
Description
FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 18 oct. 2021
- Dernière mise à jour
- 16 sept. 2024
Produits concernés
- FATEK Automation WinProladder
Correctif et mesures
FATEK Automation has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of these affected products are invited to contact FATEK customer support for additional information.