PT-2019-12096 · Delta Industrial Automation · Cncsoft Screeneditor

Natnael Samson

+1

·

Published

2019-04-17

·

Updated

2019-10-09

·

CVE-2019-10949

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Delta Industrial Automation CNCSoft ScreenEditor versions 1.00.88 and prior
Description The issue is related to multiple out-of-bounds read vulnerabilities that may be exploited, allowing information disclosure due to a lack of user input validation for processing specially crafted project files. This occurs in the DPB file parsing component, specifically affecting variables such as DescwTextLen, GCodePatternLen, and wTextLen, as well as wMessageLen.
Recommendations For Delta Industrial Automation CNCSoft ScreenEditor versions 1.00.88 and prior, consider disabling the DPB file parsing functionality until a patch is available to prevent exploitation of the out-of-bounds read vulnerabilities. Restrict access to the DPB file parsing component to minimize the risk of information disclosure. Avoid using the DescwTextLen, GCodePatternLen, wTextLen, and wMessageLen variables in the affected DPB file parsing functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10949
ZDI-19-406
ZDI-19-407
ZDI-19-409
ZDI-19-411
ZDI-19-412
ZDI-19-413
ZDI-19-414
ZDI-19-415
ZDI-19-416
ZDI-19-418
ZDI-19-419

Affected Products

Cncsoft Screeneditor