Overview
- Description
- WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior parse files and pass invalidated user data to an unsafe method call, which may allow code to be executed in the context of an administrator.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Modified
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:we-con:pi_studio:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9204D3F4-D3DA-4EA4-A932-950F721DB135", "versionEndIncluding": "4.2.34" }, { "criteria": "cpe:2.3:a:we-con:pi_studio_hmi:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "159E2064-BDBD-4354-A8AC-2894EAA39248", "versionEndIncluding": "4.1.9" } ], "operator": "OR" } ] } ]