from the lack of proper validation of user-supplied data, which could
allow reading past the end of allocated data structures, resulting in
execution of arbitrary code.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50685 | The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supplied data, which could allow reading past the end of allocated data structures, resulting in execution of arbitrary code. |
Solution
Horner Automation recommends users update to Cscape v10 SP1 https://hornerautomation.com/cscape-software-free/cscape-software/ or later.
Workaround
No workaround given by the vendor.
Fri, 13 Dec 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Dec 2024 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supplied data, which could allow reading past the end of allocated data structures, resulting in execution of arbitrary code. | |
| Title | Horner Automation Cscape Out-of-bounds Read | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-12-13T21:14:45.265Z
Reserved: 2024-12-04T21:11:42.412Z
Link: CVE-2024-12212
Updated: 2024-12-13T21:14:39.954Z
Status : Received
Published: 2024-12-13T01:15:05.810
Modified: 2024-12-13T01:15:05.810
Link: CVE-2024-12212
No data.
OpenCVE Enrichment
No data.
EUVD