Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-47134

Опубликовано: 03 окт. 2024
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier may cause a denial-of-service (DoS) condition, arbitrary code execution, and/or information disclosure because the issues exist in parsing of KPP project files.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:electronics.jtekt:kostac_plc_programming_software:*:*:*:*:*:*:*:*
Версия до 1.6.9.0 (исключая)
cpe:2.3:a:electronics.jtekt:kostac_plc_programming_software:*:*:*:*:*:*:*:*
Версия от 1.6.10.0 (включая) до 1.6.14.0 (включая)

EPSS

Процентиль: 38%
0.0017
Низкий

7.8 High

CVSS3

Дефекты

CWE-787
CWE-787

Связанные уязвимости

CVSS3: 7.8
github
больше 1 года назад

Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier may cause a denial-of-service (DoS) condition, arbitrary code execution, and/or information disclosure because the issues exist in parsing of KPP project files.

EPSS

Процентиль: 38%
0.0017
Низкий

7.8 High

CVSS3

Дефекты

CWE-787
CWE-787