CVE-2018-14814: We-Con Pi Studio

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

WECON Technology PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior lacks proper validation of user-supplied data, which may result in a read past the end of an allocated object.

Affected products

  • We-Con Pi Studio: up to and including 4.2.34
  • We-Con Pi Studio HMI: up to and including 4.1.9

Published 2019-03-27. Last modified 2026-06-17.