PT-2024-13139 · Delta Electronics · Dopsoft
Exodus Intelligence
·
Published
2024-01-18
·
Updated
2024-01-20
·
CVE-2023-43817
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Delta Electronics Delta Industrial Automation DOPSoft version 2
Description
A buffer overflow exists when parsing the
wMailContentLen field of a DPS file. An anonymous attacker can exploit this issue by enticing a user to open a specially crafted DPS file, potentially achieving code execution.Recommendations
For Delta Electronics Delta Industrial Automation DOPSoft version 2, consider avoiding the use of DPS files from untrusted sources until a patch is available. As a temporary workaround, restrict the ability to open DPS files to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dopsoft