JTEKT Electronics Corporation has an update available to handle out-of-bounds read, out-of-bounds write, and use after free vulnerabilities in its Screen Creator Advance 2, according to a report with CISA.

Successful exploitation of these vulnerabilities, discovered by Michael Heinzl, could allow an attacker to disclose information or execute arbitrary code.

The following versions of JTEKT Electronics Screen Creator Advance 2, a software program, suffer from the issues: JTEKT Electronics Screen Creator Advance 2: Ver0.1.1.4 Build01

In one issue, when an out-of-specification error is detected, an out-of-bounds write may occur because there is no error handling process.

CVE-2023-22345 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.

Schneider Bold

In addition, an out-of-bounds read may occur when processing template information because the end of data cannot be verified.

CVE-2023-22346 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.

Also, an out-of-bounds read may occur when processing file structure information because the end of data cannot be verified.

CVE-2023-22347 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.

In another issue, an out-of-bounds read may occur when processing screen management information because the end of data cannot be verified.

CVE-2023-22349 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.

In addition, an out-of-bounds read may occur when processing parts management information because the end of data cannot be verified.

CVE-2023-22350 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.

Also, an out-of-bounds read may occur when processing control management information because the end of data cannot be verified.

CVE-2023-22353 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.

In addition, when an error is detected, an out-of-bounds write may occur because there is no error handling process.

CVE-2023-22360 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.

The product sees use mainly in the critical manufacturing sector, and on a global basis.

No known public exploits specifically target these vulnerabilities. These vulnerabilities are not exploitable remotely. However, an attacker could leverage these low complexity vulnerabilities.

Japan-based JTEKT Electronics recommends users to download the following updates: Ver.0.1.1.4 Build01A and above 

For more information, click on JTEKT Electronics’ update notice.

ISSSource

Pin It on Pinterest

Share This