PT-2018-10012 · Delta Electronics · Dopsoft

B0Nd

·

Publicado

2018-06-05

·

Atualizado

2019-10-09

·

CVE-2018-10623

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior
Description The issue is related to improper restriction of operations within the bounds of a memory buffer. This occurs when the software performs read operations on a memory buffer where the position can be determined by a value read from a .dpa file. As a result, it may allow remote code execution, alter the intended control flow, allow reading of sensitive information, or cause the application to crash.
Recommendations For Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10623
ZDI-18-535
ZDI-18-537

Produtos afetados

Dopsoft