CVE ID | |
CVSS SCORE | 6.8, AV:N/AC:M/Au:N/C:P/I:P/A:P |
AFFECTED VENDORS |
Fatek Automation |
AFFECTED PRODUCTS |
PM Designer |
VULNERABILITY DETAILS |
The specific flaw exists within parsing of a pm3 file. A malformed file can lead to heap memory corruption. A remote attacker can leverage this vulnerability to cause arbitrary code execution in the context of the user. |
ADDITIONAL DETAILS |
03/03/2016 - ZDI disclosed the vulnerability to ICS-CERT to coordinate with the vendor -- Mitigation:
|
DISCLOSURE TIMELINE |
|
CREDIT | Ariele Caltabiano (kimiya) |