Aller au contenu

Fiche vulnérabilité

CVE-2021-44462 : faille élevée hornerautomation cscape envisionrv (CVSS 7.1)

Description

This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionRV v4.50.3.1 and prior. The issues result from the lack of proper validation of user-supplied data, which can result in reads and writes past the end of allocated data structures. User interaction is required to exploit this vulnerability as an attacker must trick a valid user to open a malicious HMI project file.

En bref

Sévérité
Élevée (CVSS 7.1)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
25 mars 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • hornerautomation cscape envisionrv

Références

Rechercher une autre vulnérabilité dans la base CVE