PT-2019-12096 · Delta Industrial Automation · Cncsoft Screeneditor

Natnael Samson

+1

·

Publicado

2019-04-17

·

Atualizado

2019-10-09

·

CVE-2019-10949

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Delta Industrial Automation CNCSoft ScreenEditor versions 1.00.88 and prior
Description The issue is related to multiple out-of-bounds read vulnerabilities that may be exploited, allowing information disclosure due to a lack of user input validation for processing specially crafted project files. This occurs in the DPB file parsing component, specifically affecting variables such as DescwTextLen, GCodePatternLen, and wTextLen, as well as wMessageLen.
Recommendations For Delta Industrial Automation CNCSoft ScreenEditor versions 1.00.88 and prior, consider disabling the DPB file parsing functionality until a patch is available to prevent exploitation of the out-of-bounds read vulnerabilities. Restrict access to the DPB file parsing component to minimize the risk of information disclosure. Avoid using the DescwTextLen, GCodePatternLen, wTextLen, and wMessageLen variables in the affected DPB file parsing functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10949
ZDI-19-406
ZDI-19-407
ZDI-19-409
ZDI-19-411
ZDI-19-412
ZDI-19-413
ZDI-19-414
ZDI-19-415
ZDI-19-416
ZDI-19-418
ZDI-19-419

Produtos afetados

Cncsoft Screeneditor