A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause memory corruption when an authenticated user opens a tampered log file from GP-Pro EX.
Existe una vulnerabilidad CWE-119: Restricción inadecuada de operaciones dentro de los límites de un búfer de memoria que podría provocar daños en la memoria cuando un usuario autenticado abre un archivo de registro manipulado desde GP-Pro EX.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
| Attack Vector | LOCAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | REQUIRED |
| Scope | UNCHANGED |
| Confidentiality Impact | LOW |
| Integrity Impact | LOW |
| Availability Impact | LOW |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-119
|
| [email protected] | Primary |
en
CWE-119
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| schneider-electric | pro-face_gp-pro_ex | * | <built-in method update of dict object at 0x7e60bae0e000> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:schneider-electric:pro-face_gp-pro_ex:*:*:*:*:*:*:*:* |