peter bassill · operator
$ cve CVE-2018-14818 JSON

CVE-2018-14818

9.8
CRITICAL · CVSS 3.1 · EPSS 3.5% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior have a stack-based buffer overflow vulnerability which may allow remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.49% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-121
On CISA KEVno
Public exploitnone known
Published2018-10-08
Last modified2026-06-17

Affected (2)

VendorProduct
we-conpi studio
we-conpi studio hmi

References

→ the Explorer  ·  watch your stack  ·  NVD