Labcenter Proteus 9

MonitorCVSS 7.8ICS-CERT ICSA-26-188-06Jul 7, 2026
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

Proteus versions prior to 9.2 SP0 contain buffer overflow (CWE-787, CWE-121) and use-after-free (CWE-416) vulnerabilities. Successful exploitation could allow arbitrary code execution and information disclosure on affected workstations. The vulnerability requires user interaction to open a malicious file or project.

What this means
What could happen
An attacker with access to a workstation running Proteus could execute arbitrary code and access sensitive design or simulation data, potentially allowing tampering with circuit designs or process simulations before deployment.
Who's at risk
Engineering and design teams using Labcenter Proteus for circuit design simulation and PCB design. This includes utilities with in-house controls engineering departments that use Proteus for controller hardware design, firmware development, or testing before deployment to operational systems.
How it could be exploited
An attacker would need to trick a user into opening a malicious file (such as a crafted circuit design or project file) in Proteus, or exploit the application through local network access. The buffer overflow and use-after-free vulnerabilities could then allow arbitrary code execution with the privileges of the user running Proteus.
Prerequisites
  • Local or network access to a workstation running affected Proteus version
  • User interaction required (user must open a malicious file or project)
  • No special credentials or elevated privileges required on the host system
Buffer overflow vulnerabilityUse-after-free vulnerabilityLow complexity attackUser interaction requiredLocal or network reachable
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (1)
ProductAffected VersionsFix Status
Proteus: 9.1_SP4_Build_429149.1 SP4 Build 42914Fix available
Remediation & Mitigation
0/3
Do now
0/1
HARDENINGTrain users to avoid opening Proteus project files or designs from untrusted sources
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Proteus to version 9.2 SP0 or later
Long-term hardening
0/1
HARDENINGRestrict file sharing and network access to workstations running Proteus to trusted network segments only
API: /api/v1/advisories/10c6ba67-80de-450f-a3de-f0aabb5de2ce

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Labcenter Proteus 9 | CVSS 7.8 - OTPulse