cvedb.io
CVE-2023-22424
HIGH · CVSS 7.8
EPSS exploitation probability: 0%
Published 2023-03-06T00:15:10.640 · Last modified 2026-06-17T05:35:25.310

Summary

Use-after-free vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.9.0 and earlier. With the abnormal value given as the maximum number of columns for the PLC program, the process accesses the freed memory. As a result, opening a specially crafted project file may lead to information disclosure and/or arbitrary code execution.

Affected products

jtekt — kostac_plc_programming_software

Does this affect you?

Add your gear to cvedb and we'll alert you only when jtekt ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.