PT-2018-10012 · Delta Electronics · Dopsoft

B0Nd

·

Published

2018-06-05

·

Updated

2019-10-09

·

CVE-2018-10623

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior
Description The issue is related to improper restriction of operations within the bounds of a memory buffer. This occurs when the software performs read operations on a memory buffer where the position can be determined by a value read from a .dpa file. As a result, it may allow remote code execution, alter the intended control flow, allow reading of sensitive information, or cause the application to crash.
Recommendations For Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10623
ZDI-18-535
ZDI-18-537

Affected Products

Dopsoft