JTEKT ELECTRONICS CORPORATION Vulnerabilities and Affected Products
Vulnerabilities associated with Kostac PLC Programming Software.
Products
Clear product- Screen Creator Advance 28 vulnerabilities
- Kostac PLC Programming Software (Former name: Koyo PLC Programming Software)6 vulnerabilities
- GC-A22W-CW4 vulnerabilities
- GC-A244 vulnerabilities
- GC-A24-M4 vulnerabilities
- GC-A24W-C(W)4 vulnerabilities
- GC-A254 vulnerabilities
- GC-A264 vulnerabilities
- GC-A26-J24 vulnerabilities
- GC-A26W-C(W)4 vulnerabilities
- GC-A27-C4 vulnerabilities
- GC-A28-C4 vulnerabilities
- HMI ViewJet C-more series4 vulnerabilities
- HMI GC-A2 series2 vulnerabilities
- Kostac PLC Programming Software2 vulnerabilities
- OnSinView22 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-41374HIGH | Double free issue exists in Kostac PLC Programming Software Version 1.6.11.0 and earlier. Arbitrary code may be executed by having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier because the issue exists in parsing of KPP project files. The vendor states that Kostac PLC Programming Software Version 1.6.10.0 or later implements the function which prevents a project file alteration. Therefore, to mitigate the impact of … CWE-415Sep 20, 2023 | CVSS7.8v3.1 | EPSS0.186% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41375HIGH | Use after free vulnerability exists in Kostac PLC Programming Software Version 1.6.11.0. Arbitrary code may be executed by having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1.6.9.0 and earlier because the issue exists in parsing of KPP project files. The vendor states that Kostac PLC Programming Software Version 1.6.10.0 or later implements the function which prevents a project file alteration. Therefore, to mitigate the impact of t… CWE-416Sep 20, 2023 | CVSS7.8v3.1 | EPSS0.188% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |