The affected product does not properly validate user-supplied data. If a user opens a maliciously formed CSP file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-143-04 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-06-06 17:15
Updated : 2023-06-12 16:33
NVD link : CVE-2023-31244
Mitre link : CVE-2023-31244
CVE.ORG link : CVE-2023-31244
JSON object : View
Products Affected
hornerautomation
- cscape
- cscape_envisionrv
CWE
CWE-824
Access of Uninitialized Pointer