Home
MEDIUM: 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LDefault status
unaffected
Any version
affected
Default status
unaffected
Any version
affected
Default status
unaffected
Any version
affected
Description
A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corruption and a termination of the program.
Problem types
WE-121
Product status
Any version
Any version
Any version
Credits
Amir Zaltzman and Noam Moshe of Claroty Team82 reported this vulnerability to CISA.
References
webapps.copeland.com/Dixell/Pages/SystemSoftwareUpdate
www.cisa.gov/news-events/ics-advisories/icsa-26-057-10
github.com/...p/csaf_files/OT/white/2026/icsa-26-057-10.json