CVE-2024-47134

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 3, 2024
Updated: Oct 16, 2024
CWE ID 787

Summary

CVE-2024-47134 is a serious out-of-bounds write vulnerability affecting Kostac PLC Programming Software, formerly known as Koyo PLC Programming Software, versions 1.6.14.0 and earlier. Opening a maliciously crafted project file created using versions 1.6.9.0 and earlier can lead to a denial-of-service condition, arbitrary code execution, and information disclosure. The vulnerability is due to improper handling of KPP project files during parsing. Users are advised to upgrade their software or take other protective measures to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share