Executive brief
Horner Automation Cscape, a software tool used to program and configure industrial controllers, is vulnerable to a flaw when processing specific project files. If an attacker can convince a user to open a malicious CSP file, they could potentially gain unauthorized access to sensitive information or execute harmful code on the system. This could lead to a full compromise of the workstation used to manage industrial control systems.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Horner Automation Cscape versions prior to 10.2 SP3. The flaw is triggered during the parsing of CSP files, where the application fails to properly validate the boundaries of the data being read. A local attacker can exploit this by providing a specially crafted CSP file. Successful exploitation can lead to the disclosure of sensitive memory information or the execution of arbitrary code with the privileges of the application. Horner Automation has released version 10.2 SP3 to address this vulnerability.
Affected products
- Horner Automation Cscape versions prior to 10.2 SP3
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory: CISA Advisory ICSA-26-176-03 published
- 2026-06-25: patched: Fixed in version 10.2 SP3