PT-2023-1547 · Delta Electronics · Dopsoft

Published

2023-02-02

·

Updated

2023-08-31

·

CVE-2023-0123

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Delta Electronics DOPSoft versions 4.00.16.22 and prior
Description The issue is caused by a stack-based buffer overflow. This could allow an attacker to execute arbitrary code remotely when a specially crafted file is introduced to the software. The exploitation occurs through a malformed file, which can lead to remote code execution.
Recommendations For versions 4.00.16.22 and prior, update to a version that fixes the stack-based buffer overflow issue to prevent remote code execution. As a temporary workaround, consider restricting the introduction of external files to the software until a patch is available.

Fix

Stack Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-00998
CVE-2023-0123
ZDI-23-1288
ZDI-23-1289
ZDI-23-1290
ZDI-23-1292
ZDI-23-1293

Affected Products

Dopsoft