Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-0623


Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute arbitrary code in the context of the current process.


Published

2023-03-09T22:15:51.737

Last Modified

2025-01-17T22:15:27.790

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hornerautomation cscape_envision_rv 4.60 Yes

References