Out-of-bounds write in WebAccess HMI Designer - #VU52759

 

Out-of-bounds write in WebAccess HMI Designer - #VU52759

Published: April 29, 2021


Vulnerability identifier: #VU52759
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error within the parsing of PM3 files.A remote attacker can trick a victim to open a specially crafted file or visit a malicious website, trigger out-of-bounds write and execute arbitrary code on the target system.


Affected software

WebAccess HMI Designer

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins