PT-2019-12094 · Delta Industrial Automation · Cncsoft Screeneditor
Natnael Samson
+1
·
Publicado
2019-04-17
·
Atualizado
2020-10-02
·
CVE-2019-10947
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Delta Industrial Automation CNCSoft ScreenEditor versions 1.00.88 and prior
Description
The issue arises from multiple stack-based buffer overflow vulnerabilities that can be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. This occurs due to the lack of user input validation before copying data from project files onto the stack.
Recommendations
For Delta Industrial Automation CNCSoft ScreenEditor versions 1.00.88 and prior, update to a version later than 1.00.88 to resolve the issue.
As a temporary workaround, consider restricting the use of CNCSoft ScreenEditor to minimize the risk of exploitation until a patch is available.
Avoid using CNCSoft ScreenEditor to process project files from untrusted sources until the issue is resolved.
Correção
Stack Overflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cncsoft Screeneditor