A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
The product does not correctly convert an object, resource, or structure from one type to a different type.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/106654 | third party advisory vdb entry |
https://ics-cert.us-cert.gov/advisories/ICSA-19-017-01 | mitigation third party advisory us government resource |