#VU16649 Improper input validation in Cscape - CVE-2018-19005

 

#VU16649 Improper input validation in Cscape - CVE-2018-19005

Published: December 20, 2018 / Updated: December 21, 2018


Vulnerability identifier: #VU16649
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2018-19005
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cscape
Software vendor:
Horner Automation

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to an error when processing malicious input. A remote attacker can trick the victim into opening a specially crafted POC files to read confidential information and remotely execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.


Remediation

Update to version 9.80 SP4.

External links