M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
Solution:
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://cert.vde.com/en-us/advisories/vde-2020-038 | third party advisory not applicable |
https://us-cert.cisa.gov/ics/advisories/icsa-21-021-05 | third party advisory us government resource |