CVE-2023-7206

In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, which would result in execution of arbitrary code on affected installations of Cscape.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hornerautomation:cscape:*:*:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:-:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp1:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp10:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp2:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp3:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp4:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp5:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp6:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp7:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp7.1:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp8:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp9:*:*:*:*:*:*

History

23 Jan 2024, 20:59

Type Values Removed Values Added
References () https://hornerautomation.com/cscape-software/ - () https://hornerautomation.com/cscape-software/ - Product
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-011-04 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-011-04 - Third Party Advisory, US Government Resource
First Time Hornerautomation cscape
Hornerautomation
CWE CWE-787
CPE cpe:2.3:a:hornerautomation:cscape:9.90:sp3:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp7:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp10:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp2:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:*:*:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp7.1:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:-:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp6:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp9:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp1:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp5:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp4:*:*:*:*:*:*
cpe:2.3:a:hornerautomation:cscape:9.90:sp8:*:*:*:*:*:*

16 Jan 2024, 13:56

Type Values Removed Values Added
Summary
  • (es) En las versiones 9.90 SP10 y anteriores de Horner Automation Cscape, los atacantes locales pueden aprovechar esta vulnerabilidad si un usuario abre un archivo CSP malicioso, lo que resultaría en la ejecución de código arbitrario en las instalaciones afectadas de Cscape.

15 Jan 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-15 23:15

Updated : 2024-01-23 20:59


NVD link : CVE-2023-7206

Mitre link : CVE-2023-7206

CVE.ORG link : CVE-2023-7206


JSON object : View

Products Affected

hornerautomation

  • cscape
CWE
CWE-787

Out-of-bounds Write

CWE-121

Stack-based Buffer Overflow