CVE-2021-38434CWE-194
FATEK Automation WinProladder
High · published October 18, 2021
What it is
FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in an unexpected sign extension. An attacker could leverage this vulnerability to execute arbitrary code.
The record
Technical detail
- CVSS v3.1
- 7.8 · HIGH
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00970 · 59.6th percentile
- Weakness
- CWE-194 · Unexpected Sign Extension
- Published
- 2021-10-18T12:38Z
EPSS history
Timeline