ID

VAR-202101-1991


TITLE

Century Star configuration software has input verification loopholes

Trust: 0.6

sources: CNVD: CNVD-2020-69036

DESCRIPTION

Century Star Configuration Software is an obstruction software launched by Beijing Century Changqiu Technology Co., Ltd. It is a real-time man-machine interface utility program generator. It consists of CSMaker development system and CSViewer operating system. CSMaker development system is its application Integrated development environment, in which the developer completes the design of the working condition screen, database definition, animation connection, equipment installation, command language writing, etc. The Century Star configuration software has input verification loopholes. Attackers can use this vulnerability to cause the program to crash.

Trust: 0.6

sources: CNVD: CNVD-2020-69036

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-69036

AFFECTED PRODUCTS

vendor:century changqiumodel:star configuration softwarescope:eqversion:v9.1

Trust: 0.6

sources: CNVD: CNVD-2020-69036

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-69036
value: LOW

Trust: 0.6

CNVD: CNVD-2020-69036
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-69036

EXTERNAL IDS

db:CNVDid:CNVD-2020-69036

Trust: 0.6

sources: CNVD: CNVD-2020-69036

SOURCES

db:CNVDid:CNVD-2020-69036

LAST UPDATE DATE

2022-05-04T10:18:04.897000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-69036date:2020-12-07T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-69036date:2021-01-06T00:00:00