Description
An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulnerability could result in escalation of privileges or cause a denial-of-service condition.
Problem types
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
Product status
4.8.2
Credits
Jason Huang from Cyber Threat & Product Defense Center of TXOne Networks Inc.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-062-04