In Horner Automation Cscape 9.90 and prior, improper validation of data may cause the system to write outside the intended buffer area, which may allow arbitrary code execution.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.zerodayinitiative.com/advisories/ZDI-19-903/ | vdb entry third party advisory |
https://www.us-cert.gov/ics/advisories/icsa-19-290-02 | us government resource third party advisory mitigation |