HeadlinesBriefing favicon HeadlinesBriefing.com

JTEKT HMI Designer Vulnerability CVE-2023-22345

DEV Community •
×

A critical vulnerability in JTEKT's Screen Creator Advance 2 software allows attackers to execute arbitrary code by tricking engineers into opening malicious project files. The flaw, an out-of-bounds write error, lets malformed data corrupt system memory. This affects industrial control system design workstations, posing a direct threat to engineering environments.

The software detects parsing errors but fails to abort, continuing operations until memory is compromised. This weakness in input validation and error handling is a classic vector for arbitrary code execution. Industrial engineering tools, often trusted with sensitive design data, become an entry point for network breaches if an infected file is opened.

JTEKT released a fix in version 0.1.1.4 Build01A. Organizations must identify all affected workstations, apply the update, and verify the installation. While no known exploits are active, the CVSS 7.8 score marks this as a high-severity risk. Vigilance with external project files is now essential for control system engineers.