Description
An improper restriction of operations within the bounds of a memory buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulnerability could result in escalation of privileges or cause a denial-of-service condition.
Problem types
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
Product status
Any version
v5.0.0
Credits
Jason Huang from Cyber Threat & Product Defense Center of TXOne Networks Inc.
References
software.portwell.tw/security-advisory/PWS-2026-3437.html
www.cisa.gov/news-events/ics-advisories/icsa-26-062-04
github.com/...p/csaf_files/OT/white/2026/icsa-26-062-04.json