Executive brief
AzeoTech DAQFactory, a software suite used for data acquisition and industrial automation, is vulnerable to a memory handling error. An attacker could exploit this by tricking a user into opening a specially crafted .ctl file, potentially allowing the attacker to take control of the system or execute unauthorized commands. This could lead to a complete compromise of the workstation used to manage industrial processes.
Technical details
An Access of Uninitialized Pointer (CWE-824) vulnerability exists in AzeoTech DAQFactory release 20.7 (Build 2555) and earlier. The flaw is triggered when the application attempts to access a pointer that has not been properly initialized during the parsing of a .ctl document. An attacker can exploit this by providing a malicious file to a user; upon opening the file, the application may execute arbitrary code in the context of the current process. This vulnerability requires user interaction (opening a file) and is addressed in DAQFactory Release 21.1.
Affected products
- AzeoTech DAQFactory <= 20.7 Build 2555
Timeline
- 2025-12-11: disclosed
- 2025-12-11: advisory
- 2025-12-30: other: Advisory revised (Update A)