IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Update Your Niagara Software to Address libwebp Vulnerability

UNKNOWN
CVSS 0.0
Date 2026-07-28T15:14:01+00:00
Source honeywell
Published by Honeywell

// Description

Update Your Niagara Software to Address libwebp Vulnerability Security Bulletin #: SB 2024-Tridium-1 Defect#: PSIRT-942 (CVE-2023-4863) CVSSv3: 6.8 (Medium | AV:A/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H) Summary The following releases of Niagara Framework® have been updated to address a vulnerability in the libwebp component utilized by jxBrowser. The CVE reported is CVE-2023-4863 and has been rescored as 6.8, based on the libwebp component's usage in Niagara. Solution Tridium has updated the ve

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2023-4863 0.0 unknown
CVE-2023-4863. The affected products are vulnerable to an out of bounds write vulnerability in the integrated libwebp library, that could be triggered while parsing specially crafted image files. This could allow an attacker to execute code in the context of a victim user's system. As a precondition, the user needs to add such image files, or Mendix Marketplace content that contains such image files, to their project. The exploitation happens in certain scenarios when the user opens the document that contains the image.

// Remediations (4)

Patch: Update to V8.18.27 or later version
Update to V8.18.27 or later version
Patch: Update to V7.23.37 or later version
Update to V7.23.37 or later version
Patch: Update to V9.24.0 or later version
Update to V9.24.0 or later version
Patch: Update to V10.3.1 or later version
Update to V10.3.1 or later version

// References