PT-2020-1961 · Delta Industrial Automation · Cncsoft Screeneditor

Published

2020-02-12

·

Updated

2020-03-20

·

CVE-2020-7002

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Delta Industrial Automation CNCSoft ScreenEditor versions 1.00.96 and prior
Description The issue is caused by multiple stack-based buffer overflows that can be exploited when a valid user opens a specially crafted, malicious input file. This can allow a remote attacker to execute arbitrary code in the target system by opening a specially created file in the DPB format. The vulnerability is related to the parsing of DPB files, specifically the GifName parameter.
Recommendations For versions 1.00.96 and prior, consider disabling the DPB file parsing functionality until a patch is available. Restrict access to the GifName parameter in the DPB file parsing module to minimize the risk of exploitation. Avoid using the DPB file format with the CNCSoft ScreenEditor until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01259
CVE-2020-7002
ZDI-20-308
ZDI-20-309

Affected Products

Cncsoft Screeneditor