#VU23768 Stack-based buffer overflow in PLC Editor - CVE-2019-18236
Published: December 20, 2019
PLC Editor
WECON Technology Co., Ltd.
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing project files. A remote unauthenticated attacker can send a specially crafted project file, trigger stack-based buffer overflow and execute arbitrary code on the target system under the privileges of the application.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.