[Japanese]
|
JVNDB-2023-001304
|
Multiple vulnerabilities in JTEKT ELECTRONICS Kostac PLC Programming Software
|
Kostac PLC Programming Software provided by JTEKT ELECTRONICS CORPORATION contains multiple vulnerabilities listed below.
* Out-of-bounds read (CWE-125) - CVE-2023-22419, CVE-2023-22421
* Use-after-free (CWE-416) - CVE-2023-22424
Michael Heinzl reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.
|
CVSS V3 Severity: Base Metrics 7.8 (High) [Other]
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2023-22419
|
CVSS V3 Severity:
Base Metrics:7.8 (High) [Other]
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2023-22421
|
CVSS V3 Severity:
"Base Metrics:7.8 (High) [Other]"
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact:
The above CVSS base scores have been assigned for CVE-2023-22424
|
|
JTEKT ELECTRONICS CORPORATION
- Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier
|
|
Opening a specially crafted project file may result in information disclosure and/or arbitrary code execution.
CVE-2023-22419
When processing a comment block in stage information, the end of data cannot be verified and out-of-bounds read occurs.
CVE-2023-22421
The insufficient buffer size for the PLC program instructions leads to out-of-bounds read.
CVE-2023-22424
With the abnormal value given as the maximum number of columns for the PLC program, the process accesses the freed memory.
|
[Update the software]
Update Kostac PLC Programming Software to the latest version according to the information provided by the developer.
The developer released the following versions that contain fixes for these vulnerabilities.
* Kostac PLC Programming Software Version 1.6.10.0 and above
The latest update can be obtained from the developer's website listed below.
* PLC - Download | JTEKT ELECTRONICS CORPORATION
|
JTEKT ELECTRONICS CORPORATION
|
- Out-of-bounds Read(CWE-125) [Other]
- Use After Free(CWE-416) [Other]
|
- CVE-2023-22419
- CVE-2023-22421
- CVE-2023-22424
|
- JVN : JVNVU#94966432
- National Vulnerability Database (NVD) : CVE-2023-22419
- National Vulnerability Database (NVD) : CVE-2023-22421
- National Vulnerability Database (NVD) : CVE-2023-22424
- ICS-CERT ADVISORY : ICSA-23-096-03
|
- [2023/03/06]
Web page was published
- [2023/04/10]
References : Content was added
- [2024/06/07]
References : Contents were added
|