Severity
High
Analysis Summary
CVE-2021-42705
The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.
CVE-2021-42707
The affected product is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.
Impact
- Arbitrary Code Execution
Affected Vendors
- WECON
Affected Products
- PLC Editor: Versions 1.3.8 and prior
Remediation
Refer to CISA Advisory for the patch, upgrade, or suggested workaround information.