Deserialization of Untrusted Data in LOGO! Soft Comfort - CVE-2019-10924

 

Deserialization of Untrusted Data in LOGO! Soft Comfort - CVE-2019-10924

Published: June 19, 2019


Vulnerability identifier: #VU18840
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10924
CWE-ID: CWE-502
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data. A local attacker can trick a legitimate user to open a manipulated project file, to execute arbitrary code on the targeted system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

LOGO! Soft Comfort

How to mitigate CVE-2019-10924

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vendor's recommendation:
  • Only open projects from trusted sources



LOGO! Soft Comfort - update to -

External References

Related Security Bulletins