Vulnerabilities > CVE-2018-14810 - Out-of-bounds Write vulnerability in We-Con PI Studio and PI Studio HMI

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
we-con
CWE-787

Summary

WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior parse files and pass invalidated user data to an unsafe method call, which may allow code to be executed in the context of an administrator.

Vulnerable Configurations

Part Description Count
Application
We-Con
4

Common Weakness Enumeration (CWE)