High severity7.8NVD Advisory· Published Oct 27, 2022· Updated Jun 17, 2026
CVE-2022-3378
CVE-2022-3378
Description
Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory write.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
110+ 10 more
- (no CPE)range: 0
- cpe:2.3:a:hornerautomation:cscape:*:*:*:*:*:*:*:*range: <9.90
- cpe:2.3:a:hornerautomation:cscape:9.90:-:*:*:*:*:*:*
- cpe:2.3:a:hornerautomation:cscape:9.90:sp1:*:*:*:*:*:*
- cpe:2.3:a:hornerautomation:cscape:9.90:sp2:*:*:*:*:*:*
- cpe:2.3:a:hornerautomation:cscape:9.90:sp3:*:*:*:*:*:*
- cpe:2.3:a:hornerautomation:cscape:9.90:sp4:*:*:*:*:*:*
- cpe:2.3:a:hornerautomation:cscape:9.90:sp5:*:*:*:*:*:*
- cpe:2.3:a:hornerautomation:cscape:9.90:sp6:*:*:*:*:*:*
- cpe:2.3:a:hornerautomation:cscape:9.90:sp7:*:*:*:*:*:*
- (no CPE)range: <=9.90 SP 7
Patches
Vulnerability mechanics
References
1- www.cisa.gov/uscert/ics/advisories/icsa-22-277-03nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.