Three type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Versions 2.0 and prior when processing project files. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
The product does not correctly convert an object, resource, or structure from one type to a different type.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/106524 | vdb entry third party advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-19-010-02 | third party advisory us government resource |