Pilz: Electron Vulnerabilities in PASvisu and PMI v8xx
PASvisu and PMI v8xx contain multiple vulnerabilities in the embedded Electron framework (a third-party open-source component). These vulnerabilities (buffer overflow and use-after-free flaws, CWE-787 and CWE-416) allow an attacker to achieve remote code execution with full system privileges. The vulnerabilities can be exploited locally through malicious project files or remotely over the network if the systems are accessible. An attacker gaining code execution could modify safety configurations, alter process setpoints, disable operations, or steal engineering data.
- - Network access to the PASvisu or PMI v8xx system (if exploiting remotely) - User interaction required: target user must open a malicious project file - No authentication required - Affected product versions must be in use (PASvisu <1.14.1, PMI v8xx ≤2.0.33992)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/d9ec67fd-476b-4618-9009-c651c7562c0cGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.