{"api_version":"1","generated_at":"2026-07-23T08:01:27+00:00","cve":"CVE-2019-13541","urls":{"html":"https://cve.report/CVE-2019-13541","api":"https://cve.report/api/cve/CVE-2019-13541.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-13541","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-13541"},"summary":{"title":"CVE-2019-13541","description":"In Horner Automation Cscape 9.90 and prior, an improper input validation vulnerability has been identified that may be exploited by processing files lacking user input validation. This may allow an attacker to access information and remotely execute arbitrary code.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2019-10-18 19:15:00","updated_at":"2020-10-09 12:54:00"},"problem_types":["CWE-787"],"metrics":[],"references":[{"url":"https://www.us-cert.gov/ics/advisories/icsa-19-290-02","name":"https://www.us-cert.gov/ics/advisories/icsa-19-290-02","refsource":"MISC","tags":["Mitigation","Third Party Advisory","US Government Resource"],"title":"Horner Automation Cscape | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-19-902/","name":"https://www.zerodayinitiative.com/advisories/ZDI-19-902/","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"ZDI-19-902 | Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-13541","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-13541","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"13541","vulnerable":"1","versionEndIncluding":"9.90","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hornerautomation","cpe5":"cscape","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-13541","ASSIGNER":"ics-cert@hq.dhs.gov","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Horner Automation Cscape","version":{"version_data":[{"version_value":"Cscape 9.90 and prior"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"IMPROPER INPUT VALIDATION CWE-20"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.zerodayinitiative.com/advisories/ZDI-19-902/","url":"https://www.zerodayinitiative.com/advisories/ZDI-19-902/"},{"refsource":"MISC","name":"https://www.us-cert.gov/ics/advisories/icsa-19-290-02","url":"https://www.us-cert.gov/ics/advisories/icsa-19-290-02"}]},"description":{"description_data":[{"lang":"eng","value":"In Horner Automation Cscape 9.90 and prior, an improper input validation vulnerability has been identified that may be exploited by processing files lacking user input validation. This may allow an attacker to access information and remotely execute arbitrary code."}]}},"nvd":{"publishedDate":"2019-10-18 19:15:00","lastModifiedDate":"2020-10-09 12:54:00","problem_types":["CWE-787"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hornerautomation:cscape:*:*:*:*:*:*:*:*","versionEndIncluding":"9.90","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"13541","Ordinal":"151901","Title":"CVE-2019-13541","CVE":"CVE-2019-13541","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"13541","Ordinal":"1","NoteData":"In Horner Automation Cscape 9.90 and prior, an improper input validation vulnerability has been identified that may be exploited by processing files lacking user input validation. This may allow an attacker to access information and remotely execute arbitrary code.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"13541","Ordinal":"2","NoteData":"2019-10-18","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"13541","Ordinal":"3","NoteData":"2019-10-18","Type":"Other","Title":"Modified"}]}}}