ICSA-22-055-01 FATEK Automation FvDesigner
Vulnerability Description
The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-23985
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Khangkito of VinCSS and xina1i, working with Trend Micro’s Zero Day initiative, reported these vulnerabilities to CISA.
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-055-01
- https://www.zerodayinitiative.com/advisories/ZDI-22-432/
- https://www.zerodayinitiative.com/advisories/ZDI-22-434/
- https://www.zerodayinitiative.com/advisories/ZDI-22-437/
- https://www.zerodayinitiative.com/advisories/ZDI-22-440/
- https://www.zerodayinitiative.com/advisories/ZDI-22-433/
- https://www.zerodayinitiative.com/advisories/ZDI-22-438/
More from FATEK Automation
View All →Affected Vendor
FATEK Automation
View all reports →