CVE-2023-7206

In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, which would result in execution of arbitrary code on affected installations of Cscape.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
icscertCNA
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
VendorProductVersion
hornerautomationcscape
𝑥
< 9.90
hornerautomationcscape
9.90
hornerautomationcscape
9.90:sp1
hornerautomationcscape
9.90:sp10
hornerautomationcscape
9.90:sp2
hornerautomationcscape
9.90:sp3
hornerautomationcscape
9.90:sp4
hornerautomationcscape
9.90:sp5
hornerautomationcscape
9.90:sp6
hornerautomationcscape
9.90:sp7
hornerautomationcscape
9.90:sp7.1
hornerautomationcscape
9.90:sp8
hornerautomationcscape
9.90:sp9
𝑥
= Vulnerable software versions