PT-2023-1669 · Unknown · Kostac Plc Programming

·

CVE-2023-22419

·

Published

2023-03-03

·

Updated

2023-03-13

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kostac PLC Programming Software versions 1.6.9.0 and earlier
Description The issue is related to an out-of-bounds read vulnerability that occurs when processing a comment block in stage information. This can lead to information disclosure and/or arbitrary code execution when opening a specially crafted project file. The vulnerability is caused by the inability to verify the end of data, resulting in an out-of-bounds read.
Recommendations For versions 1.6.9.0 and earlier, consider avoiding the use of comment blocks in stage information until a patch is available. As a temporary workaround, restrict access to project files from untrusted sources to minimize the risk of exploitation.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01239
CVE-2023-22419

Affected Products

Kostac Plc Programming