CVE-2025-49849 Details
Description
An Out-of-bounds Read vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end of allocated data structures.
An out-of-bounds read vulnerability has been identified in LS Electric GMWin 4 version 4.18, a programming software tool. This vulnerability arises from improper validation of user-supplied data in the parsing of PRJ files, leading to potential memory corruption issues. Exploitation of this vulnerability could allow for reading past the end of allocated data structures, creating risks for information disclosure or arbitrary code execution.
LS Electric GMWin 4 has been discontinued and is no longer available for service. Users are recommended to switch to the XGT series as a replacement. For more information, contact LS Electric.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 17, 2025CISA-ADP
Assessed Jun 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-168-02 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| LS Electric GMWin 4 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2025 | New CVE Received | [email protected] |
Volerion