CVE-2021-38434CWE-194

FATEK Automation WinProladder

High · published October 18, 2021

CVSS v3.1
7.8
EPSS
1%
Percentile
59.6
In the wild
Unconfirmed
What it is

FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project files, which could result in an unexpected sign extension. An attacker could leverage this vulnerability to execute arbitrary code.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00970 · 59.6th percentile
Weakness
CWE-194 · Unexpected Sign Extension
Published
2021-10-18T12:38Z
EPSS history
Timeline
  • 18 OCT 12:38Z
    FATEK Automation WinProladder
    cvelistv5