{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-49033","assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","state":"PUBLISHED","assignerShortName":"icscert","dateReserved":"2026-06-03T15:40:50.740Z","datePublished":"2026-07-07T21:53:38.630Z","dateUpdated":"2026-07-08T13:08:40.658Z"},"containers":{"cna":{"providerMetadata":{"orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert","dateUpdated":"2026-07-07T21:53:38.630Z"},"title":"Stack-Based Buffer Overflow in Labcenter Proteus","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-121","description":"CWE-121 Stack-based buffer overflow","type":"CWE"}]}],"affected":[{"vendor":"Labcenter","product":"Proteus","versions":[{"status":"affected","version":"9.1_SP4_Build-42914"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code.","supportingMedia":[{"type":"text/html","base64":false,"value":"The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code."}]}],"references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-06","tags":["government-resource"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":8.4,"vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"HIGH","baseScore":7.8,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}}],"solutions":[{"lang":"en","value":"Labcenter recommends ensuring you are using the latest version (9.2 SPO) of the software. Version can be found by looking at the bottom left of the Proteus home page (Version 8 or higher) or by selecting the About ISIS or About ARES option from the Help menu. Update notifications appear in the new and information section of the home page where you can activate the download and installation directly.\n\n\n\nIf you have questions or need help please contact Labcenter or your local distributor.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>Labcenter recommends ensuring you are using the latest version (9.2 SPO) of the software. Version can be found by looking at the bottom left of the Proteus home page (Version 8 or higher) or by selecting the About ISIS or About ARES option from the Help menu. Update notifications appear in the new and information section of the home page where you can activate the download and installation directly.</p><p>If you have questions or need help please contact Labcenter or your local distributor.</p>"}]}],"credits":[{"lang":"en","value":"Michael Heinzl reported these vulnerabilities to CISA.","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.2"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-08T13:07:42.514792Z","id":"CVE-2026-49033","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-08T13:08:40.658Z"}}]}}