Security & Threat Intelligence · 06.07.2026, 18:04 UTC
AzeoTech DAQFactory (Update A)
| Schweregrad | info |
|---|---|
| CVE | ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA ICS Advisories ↗ |
| Veröffentlicht | 06.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-12390, CVE-2026-12921. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious .ctl files that may lead to arbitrary code execution. The following versions of AzeoTech DAQFactory are affected:
DAQFactory <=21.1
CVSS Vendor Equipment Vulnerabilities
v3 7.8 AzeoTech AzeoTech DAQFactory Access of Resource Using Incompatible Type ('Type Confusion'), Use After Free
Background
Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-12390
In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution. View CVE Details
Affected Products AzeoTech DAQFactory
Vendor:AzeoTech Product Version:AzeoTech DAQFactory: <=21.1 Product Status:known_affected
Remediations MitigationUsers are discouraged from using documents from unknown/untrusted sources. MitigationUsers are encouraged to store .ctl files in a folder only writeable by admin-level users. MitigationUsers are encouraged to operate in "Safe Mode" when loading documents that have been out of their control. MitigationUsers are encouraged to apply a document editing password to their documents.
Relevant CWE: CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')
Metrics
CVSS Version Base Score Base Severity Vector …