VDB
CVE-2018-20346
CVE-2018-20346
PUBLISHED
CVSS 8.100000381469727 HIGH
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.
EPSS 10.31% · 95.4th percentile
Risk Scores
CVSS 3.0
8.100000381469727
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
10.31%
95.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ABB | B&R Industrial Automation GmbH Automation Studio <6.5 | |
| ABB | ABB Ability Camera Connect <=2.0.0.42 | |
| ABB | ABB B&R Automation Studio <6.5 |
Timeline
- Jan 1, 2018 CVE Published
- Jan 28, 2019 PoC Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Mar 1, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Jan 9, 2023 EPSS Score
- Mar 13, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
- Nov 8, 2023 EPSS Score
References
- https://psirt.abb.com/csaf/2026/4hzm000604.json advisory
- https://psirt.abb.com/csaf/2026/sa25p007.json advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-20346 advisory
- https://www.br-automation.com/fileadmin/SA25P007-097a386d.pdf advisory
- https://search.abb.com/library/Download.aspx?DocumentID=4HZM000604&LanguageCode=en&DocumentPartId=PDF&Action=Launch advisory