PT-2018-14277 · Delta Industrial Automation · Tpeditor
Ariele Caltabiano
+2
·
Published
2018-10-11
·
Updated
2019-10-09
·
CVE-2018-17927
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Delta Industrial Automation TPEditor versions 1.90 and prior
Description
The issue is related to multiple out-of-bounds write vulnerabilities that can be exploited by processing specially crafted project files. These files lack user input validation, which may cause the system to write outside the intended buffer area and may allow remote code execution.
Recommendations
For versions 1.90 and prior, update to a version later than 1.90 to resolve the issue.
As a temporary workaround, consider restricting the processing of project files from untrusted sources until a patch is available.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tpeditor