CVE-2023-0623
Last modified
CVE-2023-0623 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute arbitrary code in the context of the current process.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hornerautomation | Cscape Envision Rv | 4.60 |
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-040-04Third Party Advisory, US Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-040-04Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-0623?
How severe is CVE-2023-0623?
How do I fix CVE-2023-0623?
Are you affected by CVE-2023-0623?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
