CVE-2023-7206
In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, which would result in execution of arbitrary code on affected installations of Cscape.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, which would result in execution of arbitrary code on affected installations of Cscape.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.21% probability · 12th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-121, CWE-787
- Affected
- hornerautomation/cscape
- Source
- ics-cert@hq.dhs.gov
References
- https://hornerautomation.com/cscape-software/Product
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-011-04Third Party Advisory, US Government Resource
- https://hornerautomation.com/cscape-software/Product
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-011-04Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.