CVE-2026-3437 PUBLISHED

Improper Restriction of Operations within the Bounds of a Memory Buffer in Portwell Engineering Toolkits

Assigner: icscert
Reserved: 02.03.2026 Published: 03.03.2026 Updated: 03.03.2026

An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulnerability could result in escalation of privileges or cause a denial-of-service condition.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.3

Product Status

Vendor Portwell
Product Portwell Engineering Toolkits
Versions Default: unaffected
  • Version 4.8.2 is affected

Credits

  • Jason Huang from Cyber Threat & Product Defense Center of TXOne Networks Inc. finder

References

Problem Types

  • CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer CWE