High severity7.8NVD Advisory· Published Nov 15, 2022· Updated Jun 17, 2026
CVE-2022-3377
CVE-2022-3377
Description
Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory read.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:hornerautomation:cscape:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:hornerautomation:cscape:*:*:*:*:*:*:*:*range: <9.90
- cpe:2.3:a:hornerautomation:cscape:9.90:-:*:*:*:*:*:*
- cpe:2.3:a:hornerautomation:cscape:9.90:sp1:*:*:*:*:*:*
- cpe:2.3:a:hornerautomation:cscape:9.90:sp2:*:*:*:*:*:*
- cpe:2.3:a:hornerautomation:cscape:9.90:sp3:*:*:*:*:*:*
- cpe:2.3:a:hornerautomation:cscape:9.90:sp4:*:*:*:*:*:*
- cpe:2.3:a:hornerautomation:cscape:9.90:sp5:*:*:*:*:*:*
- cpe:2.3:a:hornerautomation:cscape:9.90:sp6:*:*:*:*:*:*
- (no CPE)range: 0
- (no CPE)range: <=9.90 SP 6
Patches
Vulnerability mechanics
References
1- www.cisa.gov/uscert/ics/advisories/icsa-22-277-03nvdPatchThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.